PT-2025-4818 · Node.Js · Node.Js

Published

2025-01-21

·

Updated

2025-02-05

·

CVE-2025-23088

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The affected software is Node.js, specifically all End-of-Life (EOL) versions that are no longer supported and do not receive updates, including security patches. These versions may expose systems to potential security risks due to unaddressed software issues or dependencies, such as the use of unmaintained third-party components. To mitigate this, users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support. An exploit could potentially be used to take advantage of the lack of security patches in these EOL versions. The impact of this issue could be significant, as many organizations may still be running these legacy versions of Node.js, potentially exposing a large number of systems to security risks. https://t.co/N1W60H7gbl provides more information about this issue. #Nodejs #EOL #SecurityRisks #UnmaintainedComponents #LegacyVersions #SecurityPatches

Fix

Weakness Enumeration

Related Identifiers

BIT-NODE-2025-23088
BIT-NODE-MIN-2025-23088
CVE-2025-23088

Affected Products

Node.Js