CVE-2025-55130
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.
Metrics
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
node-min20.0.0
bitnami
node-min21.0.0
bitnami
node-min22.22.3
bitnami
node-min23.0.0
bitnami
node-min24.0.0
bitnami
node-min24.16.0
bitnami
node-min25.0.0
bitnami
node-min26.3.0
IBM
App Connect EnterpriseCD 13.4.0
IBM
App Connect EnterpriseLTS 12.0.26
IBM
App Connect EnterpriseLTS 13.4.0
IBM
App Connect Enterprise< 12.0.12.28
fixed in 12.0.12.28
IBM
App Connect Enterprise< 13.0.8.1
fixed in 13.0.8.1
IBM
App Connect Enterprise< 13.0.8.2
fixed in 13.0.8.2
IBM
Concert< 3.0.0
fixed in 3.0.0
juliangruber
brace-expansion5.0.0 – 5.0.6
nodejs
undici7.23.0 – 7.28.0
nodejs
undici8.0.0 – 8.2.0
nodejs
undici8.0.0 – 8.5.0
npm
undici8.0.0
References & sources
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releasesweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48619web
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mvweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59868advisory
- https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1web
- https://github.com/nodeca/js-yamlpackage
- https://github.com/nodeca/js-yaml/releases/tag/5.2.0web
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-724g-mxrg-4qvmweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59870advisory
- https://github.com/nodeca/js-yaml/commit/39f3211a2f01b3c6982710cf21434ab7060acefeweb
- https://github.com/nodeca/js-yaml/releases/tag/5.2.1web
- https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2web
- https://nvd.nist.gov/vuln/detail/CVE-2026-45149advisory
- https://github.com/juliangruber/brace-expansion/commit/c0b095bdc52bc4c36dc88deddbadabc49f8371e5web
- https://github.com/juliangruber/brace-expansionpackage
- https://nodejs.org/en/blog/vulnerability/december-2025-security-releases
- https://nvd.nist.gov/vuln/detail/CVE-2025-55132web
- https://nvd.nist.gov/vuln/detail/CVE-2026-48936web
- https://nvd.nist.gov/vuln/detail/CVE-2026-48615web
- https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhqweb
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9678
A flaw was found in Undici.
mediumCVSSv3 5.9 - CVE-2026-9675
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-59870
A flaw was found in js-yaml, a JavaScript YAML (YAML Ain't Markup Language) parser.
highCVSSv3 7.5 - CVE-2026-59868
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-48936
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48935
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48934
A flaw was found in Node.js.
mediumCVSSv3 4.3 - CVE-2026-48933
A flaw was found in the Node.js WebCrypto implementation.
highCVSSv3 7.5 - CVE-2026-48930
A flaw was found in Node.js.
mediumCVSSv3 5.6 - CVE-2026-48928
A flaw was found in Node.js.
mediumCVSSv3 4.2 - CVE-2026-48619
A flaw was found in Node.js.
mediumCVSSv3 5.3 - CVE-2026-48618
A flaw was found in Node.js.
highCVSSv3 7.7 - CVE-2026-48615
A flaw was found in Node.js.
mediumCVSSv3 5.9 - CVE-2026-45149
A flaw was found in the brace-expansion library.
highCVSSv3 7.5 - CVE-2026-2950
A flaw was found in Lodash.
mediumCVSSv3 6.5 - CVE-2025-59464
A resource consumption flaw has been discovered in NodeJS.
mediumCVSSv3 6.5 - CVE-2025-55132
A file access flaw has been discovered in NodeJS.
lowCVSSv3 2.8 - CVE-2025-55131
A memory exposure flaw has been discovered in Node.js.
highCVSSv3 7.1