Path traversal in Node.js - CVE-2025-27210
Published: July 22, 2025 / Updated: August 1, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences affecting Windows device names like CON, PRN, and AUX. A local user can escalate privileges on the system.
Note, this vulnerability exists due to incomplete fix for #VU103223 (CVE-2025-23084).
Affected software
EasyApache
IBM Business Automation Workflow
Communications Unified Assurance
PeopleSoft Enterprise PeopleTools
Splunk Universal Forwarder
Splunk Enterprise
JD Edwards EnterpriseOne Tools
IBM App Connect Enterprise
How to mitigate CVE-2025-27210
EasyApache - update to 4 25-26
Splunk Universal Forwarder - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.5.0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.j
- cPanel EasyApache4 update for third-party components
- Multiple vulnerabilities in IBM Business Automation Workflow
- IBM App Connect Enterprise update for Node.js
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Splunk Enterprise Security update for third-party components
- Splunk Universal Forwarder update for node.js