Path traversal in Node.js - CVE-2025-23084
Published: January 22, 2025 / Updated: February 4, 2025
Vulnerability identifier: #VU103223
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23084
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to input validation error in path.join API when processing drive names in the Windows environment. A local user with ability to alter Windows drive names can escalate privileges on the system.
Affected software
Node.js
watsonx.data
EasyApache
IBM Business Automation Workflow
PowerProtect Data Manager
Communications Unified Assurance
PeopleSoft Enterprise PeopleTools
Anolis OS
openEuler
Fedora
npm
v8-devel
nodejs18
nodejs-debugsource
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs-debuginfo
nodejs
IBM App Connect Enterprise
watsonx.data
EasyApache
IBM Business Automation Workflow
PowerProtect Data Manager
Communications Unified Assurance
PeopleSoft Enterprise PeopleTools
Anolis OS
openEuler
Fedora
npm
v8-devel
nodejs18
nodejs-debugsource
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs-debuginfo
nodejs
IBM App Connect Enterprise
How to mitigate CVE-2025-23084
Install update from vendor's website.
Node.js - addressed in versions 18.20.6, 20.18.2, 22.13.1, 23.6.1
EasyApache - update to 4 25-4
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
IBM App Connect Enterprise - addressed in versions 12.0.12.11, 13.0.2.2
nodejs18 - addressed in versions 18.20.6-1.fc40, 18.20.6-1.fc41
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debugsource - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-debuginfo - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 22.16.0-1
nodejs - update to 22.16.0-1
nodejs-libs - update to 22.16.0-1
nodejs-full-i18n - update to 22.16.0-1
nodejs-docs - update to 22.16.0-1
EasyApache - update to 4 25-4
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
IBM App Connect Enterprise - addressed in versions 12.0.12.11, 13.0.2.2
nodejs18 - addressed in versions 18.20.6-1.fc40, 18.20.6-1.fc41
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debugsource - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-debuginfo - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 22.16.0-1
nodejs - update to 22.16.0-1
nodejs-libs - update to 22.16.0-1
nodejs-full-i18n - update to 22.16.0-1
nodejs-docs - update to 22.16.0-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Fedora 41 update for nodejs18
- Fedora 40 update for FEDORA
- Fedora 40 update for nodejs18
- EasyApache update for Node.js
- openEuler 24.03 LTS SP1 update for nodejs
- openEuler 24.03 LTS update for nodejs
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Anolis OS update for nodejs
- IBM watsonx.data update for Node.js