Path traversal in Node.js - CVE-2025-23084

 

Path traversal in Node.js - CVE-2025-23084

Published: January 22, 2025 / Updated: February 4, 2025


Vulnerability identifier: #VU103223
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23084
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to input validation error in path.join API when processing drive names in the Windows environment. A local user with ability to alter Windows drive names can escalate privileges on the system.


Affected software

Node.js
watsonx.data
EasyApache
IBM Business Automation Workflow
PowerProtect Data Manager
Communications Unified Assurance
PeopleSoft Enterprise PeopleTools
Anolis OS
openEuler
Fedora
npm
v8-devel
nodejs18
nodejs-debugsource
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs-debuginfo
nodejs
IBM App Connect Enterprise

How to mitigate CVE-2025-23084

Install update from vendor's website.

Node.js - addressed in versions 18.20.6, 20.18.2, 22.13.1, 23.6.1
EasyApache - update to 4 25-4
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
IBM App Connect Enterprise - addressed in versions 12.0.12.11, 13.0.2.2
nodejs18 - addressed in versions 18.20.6-1.fc40, 18.20.6-1.fc41
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debugsource - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-debuginfo - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 22.16.0-1
nodejs - update to 22.16.0-1
nodejs-libs - update to 22.16.0-1
nodejs-full-i18n - update to 22.16.0-1
nodejs-docs - update to 22.16.0-1

External References

Related Security Bulletins