Race Condition Vulnerability in Snowflake Node.js Driver
CVE-2025-46328
What is CVE-2025-46328?
The Snowflake Connector for Node.js has a vulnerability that allows local attackers to exploit a race condition in the logging configuration feature. On Linux and macOS, the driver reads a user-provided configuration file but the verification process that checks if the file is writable only by its owner can be bypassed due to a TOCTOU race condition. This flaw could allow an attacker with write access to the configuration file to gain control over the logging level and output location. The issue was addressed in version 2.0.4.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
snowflake-connector-nodejs >= 1.10.0, < 2.0.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
