Link following in node-tmp - CVE-2025-54798
Published: November 7, 2025
Vulnerability identifier: #VU118198
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54798
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to modify data on the system.
The vulnerability exists due to an insecure link following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Affected software
node-tmp
Astronomer with IBM
Storage Sentinel Anomaly Scan Engine
Guardium Data Security Center (GDSC)
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Voice Gateway
Event Streams
IBM Cognos Controller
IBM API Connect
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow
Astronomer with IBM
Storage Sentinel Anomaly Scan Engine
Guardium Data Security Center (GDSC)
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Voice Gateway
Event Streams
IBM Cognos Controller
IBM API Connect
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2025-54798
Install updates from vendor's website.
node-tmp - update to 0.2.4
Astronomer with IBM - update to 1.1.0
Voice Gateway - addressed in versions 1.0.8.16, 1.0.8.28
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
Guardium Data Security Center (GDSC) - update to 3.8.8
Event Streams - update to 12.2.2
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 3.0.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
Astronomer with IBM - update to 1.1.0
Voice Gateway - addressed in versions 1.0.8.16, 1.0.8.28
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
Guardium Data Security Center (GDSC) - update to 3.8.8
Event Streams - update to 12.2.2
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 3.0.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
External References
Related Security Bulletins
- Link following in node-tmp
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow for IBM QRadar SIEM
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Controller
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for tmp
- Multiple vulnerabilities in IBM Voice Gateway
- Astronomer with IBM update for tmp package
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM Guardium Data Security Center