Node.js Vulnerability Impacting Windows Drive Name Handling
CVE-2025-23084
5.5MEDIUM
What is CVE-2025-23084?
A security flaw has been discovered in Node.js that affects the handling of drive names on Windows systems. This issue arises when certain Node.js functions misinterpret drive names as regular paths instead of special identifiers. Consequently, even when a relative path is expected, Node.js may incorrectly reference the root directory instead of the intended location. This vulnerability specifically targets the path.join API, impacting Windows users who rely on accurate directory referencing.
Affected Version(s)
Node 4.0 < 4.*
Node 5.0 < 5.*
Node 6.0 < 6.*
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
