CVE-2025-23084A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory.
On Windows, a path that does not start with the file separator is treated as relative to the current directory.
This vulnerability affects Windows users of path.join API.
CWE-22 · Path traversal
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in a year.
CVSS E:U
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address. |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
NVD | Primary | published |
| CVSS 3.0 | 5.6 | MEDIUM | CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N |
support@hackerone.com | Secondary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update July 2025 ↗ | CPU | 2025-Q3 | Oracle PeopleSoft / OpenSearch Dashboards (Node.js) (8.60, 8.61, 8.62) |
| Oracle Critical Patch Update April 2025 ↗ | CPU | 2025-Q2 | Oracle Communications Applications / Core (Node.js) (6.0-6.1) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications Applications | Core (Node.js) | 6.0-6.1 | |
| Oracle PeopleSoft | OpenSearch Dashboards (Node.js) | 8.60, 8.61, 8.62 | 8.60 · 8.61 · 8.62 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | nodejs | node.js | generic | ≥ 18.0 and < 18.20.6 · ≥ 20.0 and < 20.18.2 · ≥ 22.0 and < 22.13.1 · ≥ 23.0 and < 23.6.1 |
| Published | 2025-01-28 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |