PT-2026-2468 · Node.Js+1 · Node.Js+1

Published

2025-01-01

·

Updated

2026-02-17

·

CVE-2025-55130

CVSS v3.1
9.1
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Node.js (affected versions not specified)
Description A flaw exists in the Node.js software platform due to incorrect path name restriction for restricted access directories. Successful exploitation of this issue could allow an attacker to compromise the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

ALSA-2026:1842
ALSA-2026:1843
ALSA-2026:2420
ALSA-2026:2421
ALSA-2026:2422
ALSA-2026:2781
BDU:2026-00545
BIT-NODE-2025-55130
BIT-NODE-MIN-2025-55130
CVE-2025-55130
MGASA-2026-0009
OESA-2026-1218
OESA-2026-1219
OESA-2026-1220
OESA-2026-1221
RHSA-2026:1842
RHSA-2026:1843
RHSA-2026:2420
RHSA-2026:2421
RHSA-2026:2422
RHSA-2026:2767
RHSA-2026:2768
RHSA-2026:2781
RHSA-2026:2782
RHSA-2026:2783
RHSA-2026:2864
RHSA-2026:2899

Affected Products

Node.Js
Rocky Linux