A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
An attacker creates a script granted access only to the current directory. By combining directories and symbolic links (symlinks) with crafted relative paths, the script can escape beyond the permitted filesystem area. The permission verification mechanism (CWE-289: Authentication Bypass by Alternate Name) does not recognize crafted paths as exceeding the allowed scope, allowing the attacker to bypass the isolation guaranteed by the permission model.
An attacker can read sensitive system files and write data outside the permitted directory, violating expected isolation. As a result, complete compromise of the system running the vulnerable Node.js process is possible.
Patches available from the vendor should be applied according to references — details in the Node.js security advisory from December 2025: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases
Node.js in versions v20, v22, v24, and v25 — affects users utilizing the Permission Model
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NNode.js
APPNodejs20.0.0 – 20.20.0 (excl.)22.0.0 – 22.22.0 (excl.)24.0.0 – 24.13.0 (excl.)25.0.0 – 25.3.0 (excl.)
Related vulnerabilities
Node.js TLS: błąd obsługi hostname z null-bajtem prowadzi do przekierowania authority
Node.js: obejście modelu uprawnień przez Unix Domain Socket
Command injection w aplikacjach Windows korzystających z CreateProcess
Path traversal w Permission Model Node.js przez monkey-patching Buffer
Path traversal w Node.js przez obiekty Uint8Array w funkcjach node:fs