VYPR
Critical severity9.8NVD Advisory· Published Aug 5, 2025· Updated Jun 17, 2026

CVE-2025-54387

CVE-2025-54387

Description

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used to check whether a path is within allowed directories is vulnerable to path prefix bypass when the allowed directories do not end with a path separator. This occurs because the check relies on a raw string prefix comparison. This is fixed in versions 1.3.2, 2.1.1 and 3.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ipxnpm
< 1.3.21.3.2
ipxnpm
>= 2.0.0-0, < 2.1.12.1.1
ipxnpm
>= 3.0.0, < 3.1.13.1.1

Affected products

3
  • Unjs/Ipx2 versions
    cpe:2.3:a:unjs:ipx:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:unjs:ipx:*:*:*:*:*:node.js:*:*range: <1.3.2
    • (no CPE)range: < 1.3.2
  • ghsa-coords
    Range: < 1.3.2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.