cbcvebase.
CVE-2025-55130
published 2026-01-20

CVE-2025-55130: A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By…

PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.63%
73.6th percentile
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiannodejs< nodejs 22.22.0+dfsg+~cs22.19.6-1 (forky)nodejs 22.22.0+dfsg+~cs22.19.6-1 (forky)
nodejsnode20.19.6 – 20.19.6
nodejsnode22.21.1 – 22.21.1
nodejsnode24.12.0 – 24.12.0
nodejsnode25.2.1 – 25.2.1
nodejsnode.js>= 20.0.0 < 20.20.020.20.0
nodejsnode.js>= 22.0.0 < 22.22.022.22.0
nodejsnode.js>= 24.0.0 < 24.13.024.13.0
nodejsnode.js>= 25.0.0 < 25.3.025.3.0
nodejsnodejs>= 0 < 22.22.2-r022.22.2-r0
nodejsnodejs>= 0 < 22.22.0-r022.22.0-r0
nodejsnodejs>= 0 < 24.13.0-r024.13.0-r0
nodejsnodejs>= 0 < 20.19.2+dfsg-1+deb13u120.19.2+dfsg-1+deb13u1
nodejsnodejs>= 0 < 22.22.0+dfsg+~cs22.19.6-122.22.0+dfsg+~cs22.19.6-1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector involves chaining directories and symlinks using crafted relative symlink paths to bypass --allow-fs-read and --allow-fs-write restrictions in Node.js Permission model
  • Affected Node.js versions are v20, v22, v24, and v25; inventory and alert on these specific major versions running with the Permission model enabled
  • In the observed attack chain, the vulnerable Node.js runtime was detected as node.exe listening on TCP port 18792; monitor for node.exe binding to this port as a potential indicator of OpenClaw/clawdbot agent activity on a host
  • Confirmed affected version in the wild: Node.js 22.12.0; prioritize detection and patching of this specific version
  • ·Red Hat notes no mitigation meeting their criteria is currently available for unpatched systems; fixed versions should be applied
  • ·Debian fixed the vulnerability in Node.js 22.22.0 (sid/forky) and 20.19.2 (trixie/bookworm); detections should account for these fixed versions to avoid false positives

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.