7.1
/ 10
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Description
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise.
This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
Basic Information
ID
CVE-2025-55130
Source
hackerone
Published
Jan 20, 2026 at 20:41
Affected Product
Vendor
nodejs
Product
node
Version
20.19.6
Affected Versions
nodejs node 20.19.6
nodejs node 22.21.1
nodejs node 24.12.0
nodejs node 25.2.1
nodejs node 22.21.1
nodejs node 24.12.0
nodejs node 25.2.1