CVE-2025-23083
published 2025-01-22CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also…
PriorityP339high7.7CVSS 3.0
AVLACLPRNUINSUCHIHAN
EPSS
0.41%
33.8th percentile
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 20.18.2+dfsg-1 (forky) | nodejs 20.18.2+dfsg-1 (forky) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.18.2 | 20.18.2 |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | >= 22.0 < 22.13.1 | 22.13.1 |
| nodejs | node | >= 23.0 < 23.6.1 | 23.6.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 20.18.2+dfsg-1 | 20.18.2+dfsg-1 |
| nodejs | nodejs | >= 0 < 20.18.2+dfsg-1 | 20.18.2+dfsg-1 |
CVSS provenance
nvdv3.07.7HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.7HIGH
vendor_debian7.7LOW
vendor_oracle7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2025-23083
vendor_oracle·2025-04-15·CVSS 7.7
CVE-2025-23083 [HIGH] Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2025-23083
Oracle Oracle Java SE Risk Matrix: Node (Node.js) vulnerability
CVE: CVE-2025-23083
CVSS: 7.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2025 (APR 2025)
Red Hat
nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
vendor_redhat·2025-01-22·CVSS 7.7
CVE-2025-23083 [HIGH] CWE-863 nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
A flaw was found in the Node.js diagnostics_channel. This vulnerability allows an attacker to reinstate and misuse worker constructors, potentially bypassing the Permission Model via hooking into events when a worker thread is created.
Statement: This vulnerability is rated as an Important severity because the diagnostics_channel utility,
Debian
CVE-2025-23083: nodejs - With the aid of the diagnostics_channel utility, an event can be hooked into whe...
vendor_debian·2025·CVSS 7.7
CVE-2025-23083 [HIGH] CVE-2025-23083: nodejs - With the aid of the diagnostics_channel utility, an event can be hooked into whe...
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 20.18.2+dfsg-1)
sid: resolved (fixed in 20.18.2+dfsg-1)
trixie: resolved (fixed in 20.18.2+dfsg-1)
OSV
CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
osv·2025-01-22·CVSS 7.7
CVE-2025-23083 [HIGH] CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
OSV
CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
osv·2025-01-22·CVSS 7.7
CVE-2025-23083 [HIGH] CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
GHSA
GHSA-wv7p-rjf3-9fr5: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
ghsa_unreviewed·2025-01-22
CVE-2025-23083 [HIGH] CWE-284 GHSA-wv7p-rjf3-9fr5: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
No detection rules found.
No public exploits indexed.
2025-01-22
Published