Description
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
INFO
Published Date :
2026-01-20T20:41:55.393Z
Last Modified :
2026-02-26T14:44:42.329Z
Source :
hackerone
AFFECTED PRODUCTS
The following products are affected by CVE-2025-55130 vulnerability.
| Vendors | Products |
|---|---|
| Nodejs |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-55130.