Node.js
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*, +2 more
- ~20
- ~22
- ~24
A vulnerability has been identified in Node.js that affects the `path.join` API on Windows systems. This issue arises from an incomplete fix for a previous vulnerability (CVE-2025-23084) and specifically impacts Windows device names such as CON, PRN, and AUX. The vulnerability allows these device names to bypass path traversal protections, potentially leading to unintended file access or manipulation.
Exploitation of this vulnerability could allow for path traversal attacks, where an attacker could manipulate file paths to access or modify files outside of the intended directory structure.
Users can update to the latest versions of Node.js in the 20.x, 22.x, and 24.x release lines to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.