Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2025-55130
Node.js: permission model bypass using crafted symlinks
Technology
Node.js
CVSS Score
9.1 / 10.0
Affected Versions
>=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0
Upstream Fix
20.20.0; 22.22.0; 24.13.0; 25.3.0
Published
January 20, 2026
OSSeva Coverage
Fixed upstream
Description
Crafted relative symlink paths let code bypass the --allow-fs-read and --allow-fs-write restrictions of the Node.js permission model, giving file read and write outside the allowed paths. Affects users of the permission model. Fixed in the January 2026 security releases: 20.20.0, 22.22.0, 24.13.0 and 25.3.0.
Is your Node.js deployment affected?
If you're running >=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0, you need this patch. Book a discovery call to get covered.