Junglewise Threat Intelligence

CVE-2025-54798: npm tmp symlink directory traversal via dir parameter

CVE-2025-54798 · Severity: low · CVSS 3.1 · Published 2025-08-06

Technologies: tmp (npm). Vendors: npm.

Executive brief

npm tmp is a Node.js library used to create temporary files and directories. Versions before 0.2.4 contain a flaw in how they validate the `dir` parameter. An attacker with local access can exploit symbolic links to bypass safety checks and create temporary files outside the intended temporary directory, potentially writing to sensitive system locations if file permissions allow.

Technical details

The vulnerability is a symlink-following bug (CWE-59) in the path validation logic of npm tmp. The `_resolvePath()` function fails to resolve symbolic links when checking whether a path remains within the system's temporary directory. If the `dir` parameter is a symlink pointing outside tmpdir, the check in `_assertIsRelative()` can be bypassed because it validates the unresolved path rather than the real resolved path. An attacker with local filesystem access can create a symlink inside tmpdir that points to an external directory, then pass this symlink as the `dir` parameter to create files outside the intended security boundary. This requires low privileges and system-level filesystem write permissions, but no user interaction. The fix, available in version 0.2.4 and later, involves calling `fs.realpathSync()` to resolve symlinks before validation.

Affected products

  • npm tmp < 0.2.4

Timeline

  • 2025-08-06: disclosed
  • 2025-08-06: patched: Fixed in version 0.2.4 and later

References

Related threats