CVE-2025-23087
CVSS 3.0 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-23087 is a cybersecurity vulnerability alert that pertains to the use of outdated and unsupported versions of Node.js. These End-of-Life (EOL) versions no longer receive security updates or patches, leaving systems vulnerable to potential risks due to unaddressed software vulnerabilities and dependencies (CWE-1104: Use of Unmaintained Third-Party Components). The continued use of these unsupported versions increases the risk of security breaches. Users are strongly advised to upgrade to actively supported versions of Node.js to ensure ongoing security updates and support.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Node.js
Affected Vendors
- OpenJS Foundation