CVE-2025-23090
CVSS 3.0 Score 7.7 of 10 (high)
Details
Published Jan 22, 2025
Summary
CVE-2025-23090 is a vulnerability affecting Node.js versions 20, 22, and 23. By utilizing the diagnostics_channel utility, an attacker can hook into the creation of an event for worker threads, including internal workers. This enables the attacker to fetch an instance of the worker and manipulate its constructor for malicious purposes. This vulnerability poses a significant risk for Permission Model users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Node.js
Affected Vendors
- OpenJS Foundation