Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-55130

Node.js: permission model bypass using crafted symlinks

Technology

Node.js

CVSS Score

9.1 / 10.0

Affected Versions

>=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0

Upstream Fix

20.20.0; 22.22.0; 24.13.0; 25.3.0

Published

January 20, 2026

OSSeva Coverage

Fixed upstream

Description

Crafted relative symlink paths let code bypass the --allow-fs-read and --allow-fs-write restrictions of the Node.js permission model, giving file read and write outside the allowed paths. Affects users of the permission model. Fixed in the January 2026 security releases: 20.20.0, 22.22.0, 24.13.0 and 25.3.0.

Upstream record: NVD · CVE.org

Is your Node.js deployment affected?

If you're running >=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0, you need this patch. Book a discovery call to get covered.