MEDIUM 5.6 Microsoft

CVE-2025-23084

A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.

Microsoft Security Update 2025-Jan: A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.

Affected Products

References

Published: 2025-01-14 · Source: Microsoft · Feed updated: 2026-08-11
This medium severity vulnerability with a CVSS score of 5.6 was published on 2025-01-14 via Microsoft. Affected: azl3 nodejs 20.14.0-8 on Azure Linux 3.0, cbl2 nodejs18 18.20.3-6 on CBL Mariner 2.0.
vulnfeed aggregates 10103 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.