Worker Thread Exposure in Node.js Affecting Various Versions
CVE-2025-23090

Currently unrated

Key Information:

Vendor

Node.js

Status
Vendor
CVE Published:
22 January 2025

What is CVE-2025-23090?

This vulnerability allows for the hooking of events whenever a worker thread is created within Node.js. It exposes not only standard workers but also internal worker instances. Malicious users can exploit this by accessing the constructor of these internal workers, leading to potential misuse and elevation of privileges among Permission Model users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

node 20.18.1

node 22.13.0

node 23.6.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.