CVE-2025-55130

EUVD-2026-3338
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise.
This vulnerability affects users of the permission model on Node.js v20,  v22,  v24, and v25.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
nodejsnode.js
20.0.0 ≤
𝑥
< 20.20.0
nodejsnode.js
22.0.0 ≤
𝑥
< 22.22.0
nodejsnode.js
24.0.0 ≤
𝑥
< 24.13.0
nodejsnode.js
25.0.0 ≤
𝑥
< 25.3.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
1:24.13.0-1.el10_1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
1:22.22.0-3.el10_1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
1:22.22.0-1.el10_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260116121421.6d880403 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260119091831.6d880403 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260119100525.489197e6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
9070020260117213814.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
9070020260117213838.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
9070020260117213748.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
9040020260211171433.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
9060020260210180816.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
9060020260210120402.rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
24.14.1-4.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
24.14.1-4.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
25.9.0-1.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
25.9.0-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
20.20.0-7.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
22.22.0-1.3.hum1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
nodejs
bookworm
18.20.4+dfsg-1~deb12u2
fixed
bookworm (security)
18.20.4+dfsg-1~deb12u2
fixed
bullseye
12.22.12~dfsg-1~deb11u4
fixed
bullseye (security)
12.22.12~dfsg-1~deb11u8
fixed
forky
24.18.0+dfsg+~cs24.13.2-1
fixed
sid
24.18.0+dfsg+~cs24.13.2-1
fixed
trixie
20.19.2+dfsg-1+deb13u2
fixed
trixie (security)
20.19.2+dfsg-1+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs20
suse enterprise server 15 SP5
20.20.0-150500.11.24.1
fixed
suse enterprise server 15 SP6
20.20.0-150600.3.15.1
fixed
nodejs20-devel
suse enterprise server 15 SP5
20.20.0-150500.11.24.1
fixed
suse enterprise server 15 SP6
20.20.0-150600.3.15.1
fixed
nodejs20-docs
suse enterprise server 15 SP5
20.20.0-150500.11.24.1
fixed
suse enterprise server 15 SP6
20.20.0-150600.3.15.1
fixed
nodejs22
suse enterprise sap 15 SP7
22.22.0-150700.3.6.1
fixed
suse enterprise server 15 SP6
22.22.0-150600.13.12.1
fixed
suse enterprise server 15 SP7
22.22.0-150700.3.6.1
fixed
nodejs22-devel
suse enterprise sap 15 SP7
22.22.0-150700.3.6.1
fixed
suse enterprise server 15 SP6
22.22.0-150600.13.12.1
fixed
suse enterprise server 15 SP7
22.22.0-150700.3.6.1
fixed
nodejs22-docs
suse enterprise sap 15 SP7
22.22.0-150700.3.6.1
fixed
suse enterprise server 15 SP6
22.22.0-150600.13.12.1
fixed
suse enterprise server 15 SP7
22.22.0-150700.3.6.1
fixed
npm20
suse enterprise server 15 SP5
20.20.0-150500.11.24.1
fixed
suse enterprise server 15 SP6
20.20.0-150600.3.15.1
fixed
npm22
suse enterprise sap 15 SP7
22.22.0-150700.3.6.1
fixed
suse enterprise server 15 SP6
22.22.0-150600.13.12.1
fixed
suse enterprise server 15 SP7
22.22.0-150700.3.6.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs20
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-debuginfo
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-debugsource
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-devel
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-docs
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-full-i18n
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-libs
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-libs-debuginfo
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.1
fixed
nodejs20-npm
Amazon Linux 2023
1:10.8.2-1.20.20.0.1.amzn2023.0.1
fixed
nodejs22
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-debuginfo
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-debugsource
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-devel
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-docs
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-full-i18n
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-libs
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-libs-debuginfo
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.1
fixed
nodejs22-npm
Amazon Linux 2023
1:10.9.4-1.22.22.0.1.amzn2023.0.1
fixed
nodejs24
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-debuginfo
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-debugsource
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-devel
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-docs
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-full-i18n
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-libs
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-libs-debuginfo
Amazon Linux 2023
1:24.13.0-1.amzn2023.0.1
fixed
nodejs24-npm
Amazon Linux 2023
1:11.6.2-1.24.13.0.1.amzn2023.0.1
fixed
v8-11.3-devel
Amazon Linux 2023
3:11.3.244.8-1.20.20.0.1.amzn2023.0.1
fixed
v8-12.4-devel
Amazon Linux 2023
3:12.4.254.21-1.22.22.0.1.amzn2023.0.1
fixed
v8-13.6-devel
Amazon Linux 2023
3:13.6.233.17-1.24.13.0.1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
nodejs
Azure Linux 3.0
0:20.14.0-12.azl3
fixed