Intel

AIKIDO-2026-10029

node is vulnerable to Path Traversal

Path TraversalCVE-2025-55130 Published Jan 14, 2026

85

High Risk

This Affects:

OSnode
0.0.1 - 20.19.6
Fixed in 20.20.0
21.0.0 - 22.21.1
Fixed in 22.22.0
23.0.0 - 24.12.0
Fixed in 24.13.0
25.0.0 - 25.2.0
Fixed in 25.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package allow a permissions bypass in the Node.js Permissions model, where crafted relative symlink paths can circumvent --allow-fs-read and --allow-fs-write restrictions. By chaining directories and symlinks, a script limited to the current directory can escape the permitted path and perform arbitrary file read or write operations, breaking isolation guarantees and potentially leading to system compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

node is vulnerable to Path Traversal in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.

How to fix this

Upgrade the node library to a patch version.