CVE-2025-55130: Node.js
Critical severity, CVSS 9.1. EPSS: 1.7% chance of exploitation in the next 30 days.
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
Affected products
- Node.js Node.js: from 20.0.0, before 20.20.0 (fixed in 20.20.0); from 22.0.0, before 22.22.0 (fixed in 22.22.0); from 24.0.0, before 24.13.0 (fixed in 24.13.0); from 25.0.0, before 25.3.0 (fixed in 25.3.0)
Published 2026-01-20. Last modified 2026-07-15.