FlawAtlas
Search the atlas
CVE-2025-55130 Critical

CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

Exploit probability 1.6%
Published January 26, 2026
Required by Not available
Last source change July 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

87 explicit affected versions

Bitnami node
Bitnami node-min

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2026:1842
related ALSA-2026:1843
related ALSA-2026:2420
related ALSA-2026:2421
related ALSA-2026:2422
related ALSA-2026:2781
related ALSA-2026:2782
related ALSA-2026:2783
related CGA-Q5RV-5G79-M742
related OPENSUSE-SU-2026:10062-1
related OPENSUSE-SU-2026:10074-1
related OPENSUSE-SU-2026:20236-1
related SUSE-SU-2026:0295-1
related SUSE-SU-2026:0301-1
related SUSE-SU-2026:0435-1
related SUSE-SU-2026:0457-1
related SUSE-SU-2026:20436-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

View original source
Open Source Vulnerabilities BIT-node-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

View original source
Open Source Vulnerabilities BIT-node-min-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

View original source

05 / REFERENCES

Further evidence