cbcvebase.
CVE-2025-23084
published 2025-07-18

CVE-2025-23084: An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability…

high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiannodejs
nodejsnode>= 20.0.0 < 20.19.420.19.4
nodejsnode>= 22.0.0 < 22.17.122.17.1
nodejsnode>= 24.0.0 < 24.4.124.4.1
nodejsnode.js>= 18.0 < 18.20.618.20.6
nodejsnode.js>= 20.0 < 20.18.220.18.2
nodejsnode.js>= 22.0 < 22.13.122.13.1
nodejsnode.js>= 23.0 < 23.6.123.6.1
nodejsnodejs>= 0 < 22.13.1-r022.13.1-r0
nodejsnodejs>= 0 < 22.13.1-r022.13.1-r0
nodejsnodejs>= 10.0 < 10.*10.*
nodejsnodejs>= 11.0 < 11.*11.*
nodejsnodejs>= 12.0 < 12.*12.*
nodejsnodejs>= 13.0 < 13.*13.*
nodejsnodejs>= 14.0 < 14.*14.*
nodejsnodejs>= 15.0 < 15.*15.*
nodejsnodejs>= 16.0 < 16.*16.*
nodejsnodejs>= 17.0 < 17.*17.*
nodejsnodejs>= 18.0 < 18.*18.*
nodejsnodejs>= 19.0 < 19.*19.*
nodejsnodejs>= 4.0 < 4.*4.*
nodejsnodejs>= 5.0 < 5.*5.*
nodejsnodejs>= 6.0 < 6.*6.*
nodejsnodejs>= 7.0 < 7.*7.*
nodejsnodejs>= 8.0 < 8.*8.*

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM