2.5
/ 10
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.
AI Analysis
The tmp package for Node.js is vulnerable to arbitrary temporary file/directory writes via a symbolic link in the 'dir' parameter, affecting versions 0.2.3 and below. This issue has been fixed in version 0.2.4.
Basic Information
ID
CVE-2025-54798
Source
GitHub_M
Published
Aug 7, 2025 at 00:04
Affected Product
Vendor
raszi
Product
node-tmp
Version
< 0.2.4
Affected Versions
raszi node-tmp < 0.2.4
CWE Classification
AI Assessment
AI Severity
Low
Vendor
raszi
Product
tmp
Version
0.2.3 and below