cbcvebase.
CVE-2025-23083
published 2025-01-22

CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also…

PriorityP339high7.7CVSS 3.0
AVLACLPRNUINSUCHIHAN
EPSS
0.41%
33.8th percentile
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiannodejs< nodejs 20.18.2+dfsg-1 (forky)nodejs 20.18.2+dfsg-1 (forky)
nodejsnode>= 10.0 < 10.*10.*
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.*12.*
nodejsnode>= 13.0 < 13.*13.*
nodejsnode>= 14.0 < 14.*14.*
nodejsnode>= 15.0 < 15.*15.*
nodejsnode>= 16.0 < 16.*16.*
nodejsnode>= 17.0 < 17.*17.*
nodejsnode>= 19.0 < 19.*19.*
nodejsnode>= 20.0 < 20.18.220.18.2
nodejsnode>= 21.0 < 21.*21.*
nodejsnode>= 22.0 < 22.13.122.13.1
nodejsnode>= 23.0 < 23.6.123.6.1
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnodejs>= 0 < 22.13.1-r022.13.1-r0
nodejsnodejs>= 0 < 22.13.1-r022.13.1-r0
nodejsnodejs>= 0 < 22.13.1-r022.13.1-r0
nodejsnodejs>= 0 < 20.18.2+dfsg-120.18.2+dfsg-1
nodejsnodejs>= 0 < 20.18.2+dfsg-120.18.2+dfsg-1

CVSS provenance

nvdv3.07.7HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.7HIGH
vendor_debian7.7LOW
vendor_oracle7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.