CVE-2025-23089

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Jan 22, 2025

Summary

CVE-2025-23089 warns users of the risks associated with utilizing End-of-Life (EOL) versions of Node.js. These unsupported versions no longer receive security patches or updates, increasing the vulnerability of systems to potential security threats. The use of such outdated software can expose systems to unaddressed vulnerabilities and dependencies (CWE-1104: Use of Unmaintained Third-Party Components). To mitigate these risks, it is highly recommended that users upgrade to actively supported versions of Node.js to ensure continued security updates and support.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share