VYPR

rpm package

almalinux/nodejs24-devel

pkg:rpm/almalinux/nodejs24-devel

Vulnerabilities (41)

  • CVE-2025-55130CriJan 20, 2026
    affected < 1:24.13.0-1.el10_1fixed 1:24.13.0-1.el10_1

    A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and

Page 3 of 3