Path traversal in Node.js - CVE-2025-27210

 

Path traversal in Node.js - CVE-2025-27210

Published: July 22, 2025 / Updated: August 1, 2025


Vulnerability identifier: #VU113118
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27210
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to input validation error when processing directory traversal sequences affecting Windows device names like CON, PRN, and AUX. A local user can escalate privileges on the system.

Note, this vulnerability exists due to incomplete fix for #VU103223 (CVE-2025-23084).


Affected software

Node.js
EasyApache
IBM Business Automation Workflow
Communications Unified Assurance
PeopleSoft Enterprise PeopleTools
Splunk Universal Forwarder
Splunk Enterprise
JD Edwards EnterpriseOne Tools
IBM App Connect Enterprise

How to mitigate CVE-2025-27210

Install updates from vendor's website.

Node.js - addressed in versions 20.19.4, 22.17.1, 24.4.1
EasyApache - update to 4 25-26
Splunk Universal Forwarder - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.5.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins