Description
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.
INFO
Published Date :
2025-01-28T04:35:15.236Z
Last Modified :
2025-11-04T21:09:38.409Z
Source :
hackerone
AFFECTED PRODUCTS
The following products are affected by CVE-2025-23084 vulnerability.
| Vendors | Products |
|---|---|
| Microsoft |
|
| Nodejs |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-23084.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact