CVE-2025-23084

CVSS 3.0 Score 5.6 of 10 (medium)

Details

Published Jan 28, 2025
CWE ID 22

Summary

CVE-2025-23084 is a vulnerability discovered in Node.js that impacts the handling of drive names in the Windows environment. Specific Node.js functions fail to recognize drive names as special, leading users to believe they are using relative paths when in fact they are referring to the root directory. This issue, unique to Windows users, can cause unexpected behavior when using the `path.join` API.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share