CVE-2025-55130

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Description

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.

Metrics

Severity
high
no public PoC known
7.1
Source: nvd-v3
75.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.7 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-04-10 13:03 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    node-min20.0.0

  • bitnami

    node-min21.0.0

  • bitnami

    node-min22.22.3

  • bitnami

    node-min23.0.0

  • bitnami

    node-min24.0.0

  • bitnami

    node-min24.16.0

  • bitnami

    node-min25.0.0

  • bitnami

    node-min26.3.0

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • IBM

    App Connect Enterprise< 12.0.12.28

    fixed in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    fixed in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    fixed in 13.0.8.2

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • juliangruber

    brace-expansion5.0.0 – 5.0.6

  • nodejs

    undici7.23.0 – 7.28.0

  • nodejs

    undici8.0.0 – 8.2.0

  • nodejs

    undici8.0.0 – 8.5.0

  • npm

    undici8.0.0

References & sources

Linked CVEs

IDCVE-2025-55130