CVE-2025-55130Disclosure(nodejs / node.js)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-289CWE-281

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-12); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-24: 1Mentions · 2026-10-04: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-24: 102-1202-1302-1402-2410-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-121
Patch1
2026-02-131
Disclosure1
2026-02-141
Disclosure1
2026-02-241
Disclosure1
Full discourse5 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Breaking the Box: bypassing Node.js Filesystem Permissions via Symlinks (CVE-2025–55130) https://xalgord.medium.com/breaking-the-box-bypassing-node-js-filesystem-permissions-via-symlinks-cve-2025-55130-0b9ad44920f9?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The text references a Medium article announcing CVE-2025‑55130, describing a symlink‑based bypass of Node.js filesystem permissions, but does not provide PoC, exploit code, or patch details.

    010971.1K
    40.2K followersView on X
  • Praveen SA 🙏@praveensacharya

    Recent Key Vulnerabilities Affecting Node.js 20 Prior to and surrounding its EOL timeline, several critical security issues were identified that impact the Node.js 20.x runtime line:😁 • HTTP/2 RST_STREAM Heap Use-After-Free (CVE-2026-56848): A High severity flaw where a remote, unauthenticated attacker can trigger a process crash. The HTTP/2 server can force a stream write that re-enters session memory allocation while it is still processing received frames, resulting in an availability denial-of-service (DoS). • Permission Model Radix-Tree Over-Grant (CVE-2026-58043): A High severity issue where a flaw in prefix boundary handling allows an attacker with partial filesystem access to read or write to paths completely outside the intended restricted allowlist. • HTTP/2 Resource Exhaustion (CVE-2026-56846): A High severity memory flaw where retained header blocks escape the maxSessionMemory limit, allowing a remote client to consume all process memory and force a crash. • Bypass File System Permissions via Symlinks (CVE-2025-55130): A High severity flaw in the Permissions model where path restrictions (--allow-fs-read and --allow-fs-write) can be escaped using relative symbolic links, enabling unauthorized system file access. • TLS Callback Exceptions DoS (CVE-2026-21637): A Medium severity bug where synchronous exceptions thrown inside pskCallback or ALPNCallback bypass standard TLS error paths, causing file descriptor leaks or sudden process termination.

    0000065
    308 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "Breaking the Box: bypassing Node.js Filesystem Permissions via Symlinks (CVE-2025–55130)" by Krishna Kumar #BugBounty #Cybersecurity #Hacking #InfoSec https://infosecwriteups.com/breaking-the-box-bypassing-node-js-filesystem-permissions-via-symlinks-cve-2025-55130-0b9ad44920f9

    Post summary

    The post announces a new Node.js filesystem permission bypass vulnerability (CVE-2025-55130) and links to a writeup detailing the issue.

    0000082
    478 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "Breaking the Box: bypassing Node.js Filesystem Permissions via Symlinks (CVE-2025–55130)" by Krishna Kumar #BugBounty #Cybersecurity #Hacking #InfoSec https://xalgord.medium.com/breaking-the-box-bypassing-node-js-filesystem-permissions-via-symlinks-cve-2025-55130-0b9ad44920f9

    Post summary

    The article announces CVE-2025‑55130, detailing a Node.js filesystem permissions bypass via symlinks, but does not provide PoC code, patch information, or evidence of active exploitation.

    00000121
    476 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #SUSE just patched Node.js 20 (CVE-2025-55130). The CVSS 7.5 is almost misleading—this isn't complex to execute. HTTP/2 continuation flood = CPU pegged at 100%. No auth needed. Just packets. Read more: 👉 https://tinyurl.com/53b3zctf #Security https://t.co/WBMwf0QSeW

    Post summary

    SUSE has released a patch for CVE‑2025‑55130 in Node.js 20, highlighting that the vulnerability can be exploited via an HTTP/2 continuation flood that overwhelms CPU resources, despite a moderate CVSS score.

    0000050
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more