CVE-2025-55130 is a high-severity path-restriction bypass in the Node.js Permissions model. Crafted relative symbolic-link paths, including chains of directories and symlinks, can evade the --allow-fs-read and --allow-fs-write filesystem restrictions. A script authorized only for its current directory can escape the intended allowed path and access sensitive files. The issue affects permission-model users of Node.js 20.x, 22.x, 24.x, and 25.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Node.js proof-of-concept exploit for CVE-2025-55130 (Node.js Permission Model symlink escape). It demonstrates bypassing --allow-fs-read/--allow-fs-write restrictions by creating a deep directory chain within the allowed path, placing a symlink (link) that points to an absolute path (__dirname), and then appending enough ../ traversal segments after the symlink so that the permission check (performed on the pre-resolution string) passes while the resolved path escapes the sandbox. Structure/purpose: - README.md: Explains the vulnerability, affected versions (20.x<20.20.0, 22.x<22.22.0, 24.x<24.13.0, 25.x<25.3.0), and usage. - check.js: Local-only version range checker using process.version; not an exploit. - exploit.js: Main arbitrary file read PoC. Default target is /etc/passwd; accepts a target path as argv[2]. Builds ./pwn/... chain, symlinks to __dirname, computes traversal depth from __dirname, and reads via fs.readFileSync on the crafted path. - exploit_write.js: Arbitrary file write PoC. Default target is /tmp/pwned_<timestamp>.txt; accepts target path and content via argv. Uses fs.writeFileSync on the crafted escaped path. - exfil.js: Bulk exfiltration helper that iterates a hardcoded list of common sensitive Linux and $HOME files (SSH keys, AWS creds, Docker config, shell history, etc.) and attempts to read each via the same symlink+traversal technique; prints a small preview and stats. Capabilities: - Sandbox escape for filesystem operations under Node’s Permission Model. - Arbitrary file read (single target) and mass file read/exfiltration. - Arbitrary file write outside the allowed directory (can be used for persistence/priv-esc depending on environment). No network C2/endpoints are present; all actions are local filesystem operations. Cleanup routines remove created directories (./pwn, ./wpwn, ./exfil_chain) after execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Node.js file-permissions bypass affecting installed Node.js packages on Rocky Linux 9.
A critical vulnerability patched in Oracle Communications that can lead to remote code execution.
Filesystem permissions bypass vulnerability in Node.js.
A high-severity Node.js vulnerability that could allow reading sensitive files via crafted relative symlink paths (as described in the content).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.