HIGH 7.7 Microsoft
CVE-2025-23083
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Microsoft Security Update 2025-Jan: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Affected Products
- azl3 nodejs 20.14.0-8 on Azure Linux 3.0
- azl3 nodejs 20.14.0-4 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-23083
- https://nvd.nist.gov/vuln/detail/CVE-2025-23083
This high severity vulnerability with a CVSS score of 7.7 was published on 2025-01-14 via Microsoft. Affected: azl3 nodejs 20.14.0-8 on Azure Linux 3.0, azl3 nodejs 20.14.0-4 on Azure Linux 3.0.
vulnfeed aggregates 10103 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.