CVE-2025-55130
EUVD-2026-333820.01.2026, 21:16
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nodejs | node.js | 20.0.0 ≤ 𝑥 < 20.20.0 |
| nodejs | node.js | 22.0.0 ≤ 𝑥 < 22.22.0 |
| nodejs | node.js | 24.0.0 ≤ 𝑥 < 24.13.0 |
| nodejs | node.js | 25.0.0 ≤ 𝑥 < 25.3.0 |
𝑥
= Vulnerable software versions
Debian Releases