← Back

CVE-2025-55132

nvd nist
Published: Jan 20, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

Affected (4)

Products: Nodejs: Node.js
1 product
Node.js
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 20.0.0 to 20.20.0
From 22.0.0 to 22.22.0
From 24.0.0 to 24.13.0
From 25.0.0 to 25.3.0

References (1)

Source: support@hackerone.com
Release NotesVendor Advisory

Timeline

No history available yet.