Intel

AIKIDO-2026-10035

node is vulnerable to Improper Access Control

Improper Access ControlCVE-2025-55132 Published Jan 14, 2026

30

Low Risk

This Affects:

OSnode
0.0.1 - 20.19.6
Fixed in 20.20.0
21.0.0 - 22.21.1
Fixed in 22.22.0
23.0.0 - 24.12.0
Fixed in 24.13.0
25.0.0 - 25.2.0
Fixed in 25.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package allow improper enforcement of file system permissions in the Node.js permission model, where futimes() can be used to modify file access and modification timestamps even when the process has only read permissions. Unlike utimes(), futimes() does not apply the expected write-permission checks, enabling metadata changes in read-only directories and potentially allowing attackers to obscure activity and undermine the reliability of logs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

node is vulnerable to Improper Access Control in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.

How to fix this

Upgrade the node library to a patch version.