CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-23083: With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to...

7.7 CVSS

Description

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.

This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

Classification

CVE ID: CVE-2025-23083

CVSS Base Severity: HIGH

CVSS Base Score: 7.7

Affected Products

Vendor: nodejs

Product: node

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.71% (scored less or equal to compared to others)

EPSS Date: 2025-02-20 (when was this score calculated)

References

https://nodejs.org/en/blog/vulnerability/january-2025-security-releases

Timeline