CVE detail
CVE-2025-55130
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJan 20, 2026, 9:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2431352bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/security/cve/CVE-2025-55130access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:7387access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:7386access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6431access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6402access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2899access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2864access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2783access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2782access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2781access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2768access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2767access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2422access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2421access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:2420access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:1843access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:1842access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 20, 2026, 9:16 PM No excerpt available.
Vendor Advisorynodejs.orgJan 20, 2026, 9:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48618CVSS 6.5 · Medium
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname…
- CVE-2026-23556CVSS 9.4 · Critical
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer no…
- CVE-2026-58494CVSS 6.5 · Medium
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching Fi…
- CVE-2026-9701CVSS 9.8 · Critical
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the passw…
- CVE-2026-55075CVSS 7.4 · High
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chaine…
- CVE-2026-4360CVSS 2.0 · Low
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could e…