CVE-2025-23083

Name
CVE-2025-23083
Description
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
support@hackerone.com https://nodejs.org/en/blog/vulnerability/january-2025-security-releases
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20250228-0008/

Match rules

CPE URI Source package Min version Max version
node >= 0 <= 20.18.1
node >= 0 <= 22.13.0
node >= 0 <= 23.6.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nodejs edge-main 22.13.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs 3.21-main 22.13.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
openjdk17 edge-community 17.0.15_p6-r0 Simon Frankenberger <simon-alpine@fraho.eu> fixed
openjdk21 edge-community 21.0.7_p6-r0 Simon Frankenberger <simon-alpine@fraho.eu> fixed
openjdk17 3.21-community 17.0.15_p6-r0 Simon Frankenberger <simon-alpine@fraho.eu> fixed
openjdk21 3.21-community 21.0.7_p6-r0 Simon Frankenberger <simon-alpine@fraho.eu> fixed