Description

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

INFO

Published Date :

2025-01-22T01:11:30.802Z

Last Modified :

2026-02-26T19:08:58.894Z

Source :

hackerone
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23083 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Rhel Eus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact