CVE-2025-27210 is an incomplete fix for CVE-2025-23084 in Node.js on Windows. The flaw affects the path.join API's handling of reserved Windows device names, including CON, PRN, and AUX. Node.js versions from 4.0 through versions before 20.19.4, 22.17.1, and 24.4.1 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-27210, a high-severity path traversal vulnerability in Node.js on Windows. The exploit is implemented in a single Python script (CVE-2025-27210.py) and is accompanied by a detailed README.md explaining the vulnerability, affected versions, and mitigation steps. The exploit works by sending a specially crafted HTTP request to a vulnerable Node.js application's file endpoint, using a path traversal sequence that leverages Windows reserved device names (such as 'AUX') to bypass path restrictions. The script allows the user to specify the target URL, the file to read, and the HTTP method (GET or POST). If successful, it retrieves and displays the contents of arbitrary files from the Windows filesystem. The exploit targets Node.js versions 20.x < 20.19.4, 22.x < 22.17.1, and 24.x < 24.4.1 running on Windows. The repository is structured simply, with the main exploit logic in the Python script and comprehensive documentation in the README.
This repository provides a comprehensive proof-of-concept (PoC) for exploiting CVE-2025-27210, a path traversal vulnerability in Node.js applications running on Windows. The vulnerability arises from improper handling of reserved device names (such as CON, AUX, PRN, NUL, COM1, LPT1, etc.) in conjunction with path traversal sequences and the use of path normalization or joining functions. The repository contains both exploit scripts (in Python) and vulnerable Node.js applications for testing. Key files: - 'App_CVE-2025-27210/CVE-2025-27210.py' and 'App_CVE-2025-27210/CVE-2025-27210_mod.py': Python scripts that automate the exploitation by sending crafted HTTP requests to a target Node.js endpoint, attempting to retrieve arbitrary files from the Windows filesystem. - 'App_CVE-2025-27210/server.js' and 'App_CVE-2025-27210_bis/app.js': Node.js applications that demonstrate the vulnerable behavior, exposing endpoints that can be targeted by the exploit scripts. - 'App_CVE-2025-27210/views/index.ejs' and related static files: Provide a web interface for manual testing of path normalization and joining. The exploit works by sending HTTP GET or POST requests to endpoints such as '/files' or '/file/:filename' with a specially crafted path that includes reserved device names and traversal sequences. If the application is vulnerable, it will return the contents of the specified file, such as 'C:\Windows\win.ini'. The repository is structured to facilitate both automated and manual testing of the vulnerability, making it a valuable resource for security researchers and developers seeking to understand or validate the impact of CVE-2025-27210.
This repository provides a Python proof-of-concept exploit for CVE-2025-27210, a path traversal vulnerability affecting Node.js applications running on Windows. The exploit leverages the mishandling of Windows reserved device names (such as AUX) in conjunction with directory traversal sequences to bypass path normalization and access arbitrary files on the server. The main script, 'CVE-2025-27210_NodeJS_Path_Traversal_Exploiter.py', accepts a target URL, a file path, and an HTTP method (GET or POST) as arguments. It constructs a malicious path, encodes it, and sends it to the specified endpoint. If the server is vulnerable, the script retrieves and displays the contents of the targeted file. The repository includes a README with usage instructions and a LICENSE file. No hardcoded endpoints are present, but the script is designed to target endpoints like '/files' or '/download' on the vulnerable server. The exploit is a functional PoC and does not include weaponized or automated post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.