Permission Model Flaw in Node.js Affects File Metadata Management
CVE-2025-55132

2.8LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
20 January 2026

What is CVE-2025-55132?

A significant flaw in the permission model of Node.js allows unauthorized modification of file access and modification timestamps. This occurs through the use of the futimes() function, which bypasses traditional write permission checks. As a result, even processes with read-only access can alter file metadata in read-only directories. This vulnerability poses a risk of obscuring activity logs, thereby diminishing their reliability and integrity. The issue affects multiple versions of Node.js (v20, v22, v24, and v25), necessitating immediate attention from users relying on accurate logging and file management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

node 20.19.6

node 22.21.1

node 24.12.0

References

CVSS V3.0

Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.