Junglewise Threat Intelligence

CVE-2025-55130: Node.js permission model bypass via crafted symlinks

CVE-2025-55130 · Severity: critical · CVSS 9.1 · Published 2026-01-20

Technologies: Red Hat Enterprise Linux AppStream, Node.js Foundation Node.Js. Vendors: Red Hat.

Executive brief

A security flaw has been identified in Node.js's permission system, which is used to restrict what files a script can access. An attacker can use specially crafted file shortcuts (symlinks) to trick the system into granting access to sensitive files outside of the allowed folders. This could lead to unauthorized viewing or modification of critical system data, potentially compromising the entire server.

Technical details

A path traversal vulnerability exists in the Node.js Permission Model (experimental) due to improper handling of relative symbolic links. By chaining directories and symlinks, an attacker can bypass the restrictions imposed by the --allow-fs-read and --allow-fs-write flags. This allows a script that should be restricted to a specific directory to access or modify arbitrary files on the host file system. The vulnerability affects Node.js versions 20.x, 22.x, 24.x, and 25.x. Users are advised to update to the security releases provided in January 2026.

Affected products

  • Node.js Foundation Node.js 20.x, 22.x, 24.x, 25.x
  • Red Hat Enterprise Linux AppStream 8, 9, 10

Timeline

  • 2026-01-13: patched: Node.js security releases published
  • 2026-01-20: disclosed: NVD publication date
  • 2026-02-03: advisory: Red Hat security advisory issued

References

Related threats