FlawAtlas
Search the atlas
CVE-2025-23083 Not scored

CVE-2025-23083

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

Exploit probability 0.4%
Published January 22, 2025
Required by Not available
Last source change June 24, 2026

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2025:1351
related ALSA-2025:1443
related ALSA-2025:1611
related ALSA-2025:1613
related CGA-HQHM-VF63-2JPH
related OPENSUSE-SU-2025:14706-1
related OPENSUSE-SU-2025:15802-1
related RLSA-2025:1443
related SUSE-SU-2025:0232-1
related SUSE-SU-2025:0237-1
related SUSE-SU-2025:0284-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-23083

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

View original source

05 / REFERENCES

Further evidence