CVE-2025-23084
published 2025-07-18CVE-2025-23084: An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
1.58%
73.8th percentile
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.
This vulnerability affects Windows users of `path.join` API.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | — | — |
| nodejs | node | >= 20.0.0 < 20.19.4 | 20.19.4 |
| nodejs | node | >= 22.0.0 < 22.17.1 | 22.17.1 |
| nodejs | node | >= 24.0.0 < 24.4.1 | 24.4.1 |
| nodejs | node.js | >= 18.0 < 18.20.6 | 18.20.6 |
| nodejs | node.js | >= 20.0 < 20.18.2 | 20.18.2 |
| nodejs | node.js | >= 22.0 < 22.13.1 | 22.13.1 |
| nodejs | node.js | >= 23.0 < 23.6.1 | 23.6.1 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 10.0 < 10.* | 10.* |
| nodejs | nodejs | >= 11.0 < 11.* | 11.* |
| nodejs | nodejs | >= 12.0 < 12.* | 12.* |
| nodejs | nodejs | >= 13.0 < 13.* | 13.* |
| nodejs | nodejs | >= 14.0 < 14.* | 14.* |
| nodejs | nodejs | >= 15.0 < 15.* | 15.* |
| nodejs | nodejs | >= 16.0 < 16.* | 16.* |
| nodejs | nodejs | >= 17.0 < 17.* | 17.* |
| nodejs | nodejs | >= 18.0 < 18.* | 18.* |
| nodejs | nodejs | >= 19.0 < 19.* | 19.* |
| nodejs | nodejs | >= 4.0 < 4.* | 4.* |
| nodejs | nodejs | >= 5.0 < 5.* | 5.* |
| nodejs | nodejs | >= 6.0 < 6.* | 6.* |
| nodejs | nodejs | >= 7.0 < 7.* | 7.* |
| nodejs | nodejs | >= 8.0 < 8.* | 8.* |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
osv5.5MEDIUM
vendor_oracle5.6MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle PeopleSoft Risk Matrix: OpenSearch Dashboards (Node.js) — CVE-2025-23084
vendor_oracle·2025-07-15·CVSS 5.6
CVE-2025-23084 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: OpenSearch Dashboards (Node.js) — CVE-2025-23084
Oracle Oracle PeopleSoft Risk Matrix: OpenSearch Dashboards (Node.js) vulnerability
CVE: CVE-2025-23084
CVSS: 5.6
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Node.js) — CVE-2025-23084
vendor_oracle·2025-04-15·CVSS 5.6
CVE-2025-23084 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Node.js) — CVE-2025-23084
Oracle Oracle Communications Applications Risk Matrix: Core (Node.js) vulnerability
CVE: CVE-2025-23084
CVSS: 5.6
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2025 (APR 2025)
Debian
CVE-2025-23084: nodejs - A vulnerability has been identified in Node.js, specifically affecting the handl...
vendor_debian·2025·CVSS 5.5
CVE-2025-23084 [MEDIUM] CVE-2025-23084: nodejs - A vulnerability has been identified in Node.js, specifically affecting the handl...
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2025-27210: nodejs - An incomplete fix has been identified for CVE-2025-23084 in Node.js, specificall...
vendor_debian·2025·CVSS 5.5
CVE-2025-27210 [MEDIUM] CVE-2025-27210: nodejs - An incomplete fix has been identified for CVE-2025-23084 in Node.js, specificall...
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-x33r-pvvq-wjrh: An incomplete fix has been identified for CVE-2025-23084 in Node
ghsa_unreviewed·2025-07-19·CVSS 5.5
CVE-2025-27210 [MEDIUM] CWE-22 GHSA-x33r-pvvq-wjrh: An incomplete fix has been identified for CVE-2025-23084 in Node
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.
This vulnerability affects Windows users of `path.join` API.
OSV
CVE-2025-23084: A vulnerability has been identified in Node
osv·2025-01-28·CVSS 5.5
CVE-2025-23084 [MEDIUM] CVE-2025-23084: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.
OSV
CVE-2025-23084: A vulnerability has been identified in Node
osv·2025-01-28·CVSS 5.5
CVE-2025-23084 [MEDIUM] CVE-2025-23084: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory.
On Windows, a path that does not start with the file separator is treated as relative to the current directory.
This vulnerability affects Windows users of `path.join` API.
GHSA
GHSA-37v4-cwgp-x353: A vulnerability has been identified in Node
ghsa_unreviewed·2025-01-28
CVE-2025-23084 [MEDIUM] CWE-22 GHSA-37v4-cwgp-x353: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory.
On Windows, a path that does not start with the file separator is treated as relative to the current directory.
This vulnerability affects Windows users of `path.join` API.
No detection rules found.
No public exploits indexed.
2025-07-18
Published