Medium severity5.5NVD Advisory· Published Jan 28, 2025· Updated Jun 17, 2026
CVE-2025-23084
CVE-2025-23084
Description
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory.
On Windows, a path that does not start with the file separator is treated as relative to the current directory.
This vulnerability affects Windows users of path.join API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- osv-coords18 versionspkg:bitnami/nodepkg:bitnami/node-minpkg:apk/chainguard/nodejs-16-docpkg:apk/wolfi/nodejs-16pkg:apk/wolfi/nodejs-16-docpkg:apk/wolfi/nodejs-21pkg:apk/chainguard/nodejs-21-docpkg:apk/chainguard/nodejs-16pkg:deb/ubuntu/[email protected]~dfsg2-2ubuntu1.2+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]~dfsg-1ubuntu4.2+esm3?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]~dfsg-2ubuntu0.4+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]~dfsg-3ubuntu1.6?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~dfsg-1ubuntu3.6?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+dfsg-1ubuntu1?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]+dfsg-6ubuntu5?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg-1ubuntu2?arch=source&distro=pluckypkg:apk/chainguard/nodejs-21pkg:apk/wolfi/nodejs-21-doc
< 18.20.6+ 17 more
- (no CPE)range: < 18.20.6
- (no CPE)range: < 18.20.6
- (no CPE)range: < 16.20.2-r16
- (no CPE)range: < 16.20.2-r16
- (no CPE)range: < 16.20.2-r16
- (no CPE)range: < 21.7.3-r13
- (no CPE)range: < 21.7.3-r13
- (no CPE)range: < 16.20.2-r16
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 21.7.3-r13
- (no CPE)range: < 21.7.3-r13
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.