Race Condition Vulnerability in Snowflake Node.js Driver
CVE-2025-46328

7HIGH

Key Information:

Vendor
CVE Published:
28 April 2025

What is CVE-2025-46328?

The Snowflake Connector for Node.js has a vulnerability that allows local attackers to exploit a race condition in the logging configuration feature. On Linux and macOS, the driver reads a user-provided configuration file but the verification process that checks if the file is writable only by its owner can be bypassed due to a TOCTOU race condition. This flaw could allow an attacker with write access to the configuration file to gain control over the logging level and output location. The issue was addressed in version 2.0.4.

Affected Version(s)

snowflake-connector-nodejs >= 1.10.0, < 2.0.4

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-46328 : Race Condition Vulnerability in Snowflake Node.js Driver