CVE-2025-54798

EUVD-2025-23895
tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.5 LOW
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.12%
Affected Products (NVD)
VendorProductVersion
raszitmp
𝑥
< 0.2.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-tmp
bookworm
0.2.2+dfsg+~0.2.3-1.1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
0.2.1+dfsg-1+deb11u1
fixed
forky
0.2.7+dfsg+~0.2.6-1
fixed
sid
0.2.7+dfsg+~0.2.6-1
fixed
trixie
0.2.2+dfsg+~0.2.3-1.1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tmp
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
xenial
needs-triage