node is vulnerable to Path Traversal
85
High Risk
Affected versions of the package allow a permissions bypass in the Node.js Permissions model, where crafted relative symlink paths can circumvent --allow-fs-read and --allow-fs-write restrictions. By chaining directories and symlinks, a script limited to the current directory can escape the permitted path and perform arbitrary file read or write operations, breaking isolation guarantees and potentially leading to system compromise.
You are affected if you are using a version that falls within the vulnerable range.
node is vulnerable to Path Traversal in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant