CVE 2.5 LOW

tmp does not restrict arbitrary temporary file / directory write via symbolic link `dir` parameter_CVE-2025-54798

2.5 / 10
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

AI Analysis

The tmp package for Node.js is vulnerable to arbitrary temporary file/directory writes via a symbolic link in the 'dir' parameter, affecting versions 0.2.3 and below. This issue has been fixed in version 0.2.4.

Basic Information

ID CVE-2025-54798
Source GitHub_M
Published Aug 7, 2025 at 00:04

Affected Product

Vendor raszi
Product node-tmp
Version < 0.2.4
Affected Versions raszi node-tmp < 0.2.4

CWE Classification

AI Assessment

AI Severity Low
Vendor raszi
Product tmp
Version 0.2.3 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.