CVE-2025-23084

CWE-22Path Traversal9 documents7 sources
Severity
5.5MEDIUM
EPSS
1.3%
top 20.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateJul 15

Description

A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5nodejs/node20.0.020.19.4+22
CVEListV5nodejs/nodejs4.04.*+15
NVDnodejs/node.js18.018.20.6+3
Alpinenodejs< 22.13.1-r0+1

🔴Vulnerability Details

4
OSV
CVE-2025-23084: A vulnerability has been identified in Node2025-01-28
CVEList
CVE-2025-23084: A vulnerability has been identified in Node2025-01-28
OSV
CVE-2025-23084: A vulnerability has been identified in Node2025-01-28
GHSA
GHSA-37v4-cwgp-x353: A vulnerability has been identified in Node2025-01-28

📋Vendor Advisories

3
Oracle
Oracle Oracle PeopleSoft Risk Matrix: OpenSearch Dashboards (Node.js) — CVE-2025-230842025-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Node.js) — CVE-2025-230842025-04-15
Debian
CVE-2025-23084: nodejs - A vulnerability has been identified in Node.js, specifically affecting the handl...2025

💬Community

1
HackerOne
Windows Device Names (CON, PRN, AUX) Bypass Path Traversal Protection in path.normalize()2025-07-15
CVE-2025-23084 (MEDIUM CVSS 5.5) | A vulnerability has been identified | cvebase.io