Link following in node-tmp - CVE-2025-54798

 

Link following in node-tmp - CVE-2025-54798

Published: November 7, 2025


Vulnerability identifier: #VU118198
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54798
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to modify data on the system.

The vulnerability exists due to an insecure link following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.


Affected software

node-tmp
Astronomer with IBM
Storage Sentinel Anomaly Scan Engine
Guardium Data Security Center (GDSC)
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Voice Gateway
Event Streams
IBM Cognos Controller
IBM API Connect
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-54798

Install updates from vendor's website.

node-tmp - update to 0.2.4
Astronomer with IBM - update to 1.1.0
Voice Gateway - addressed in versions 1.0.8.16, 1.0.8.28
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
Guardium Data Security Center (GDSC) - update to 3.8.8
Event Streams - update to 12.2.2
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 3.0.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1

External References

Related Security Bulletins