Race Condition Vulnerability in Snowflake Node.js Driver
CVE-2025-46328
7HIGH
What is CVE-2025-46328?
The Snowflake Connector for Node.js has a vulnerability that allows local attackers to exploit a race condition in the logging configuration feature. On Linux and macOS, the driver reads a user-provided configuration file but the verification process that checks if the file is writable only by its owner can be bypassed due to a TOCTOU race condition. This flaw could allow an attacker with write access to the configuration file to gain control over the logging level and output location. The issue was addressed in version 2.0.4.
Affected Version(s)
snowflake-connector-nodejs >= 1.10.0, < 2.0.4