Loading HuntDB...

node.js

7 Products 60 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
16
Medium
11
Low
9

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 2 CVEs
Last Year 14 CVEs

Recent CVEs

View all
CVE-2024-27980 HIGH 5 months, 3 weeks ago

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary …

CVE-2024-37372 LOW 5 months, 3 weeks ago

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true.…

Related Security News

Re: Node.js EOL CVEs: CVE-2025-23087, CVE-2025-23088, CVE-2025-23089
2025-01-28 14:07 Seclists.org

Posted by Pete Allor on Jan 28Florian, I think you miss what actually is done and how, with whom / what. Pete

Re: Node.js EOL CVEs: CVE-2025-23087, CVE-2025-23088, CVE-2025-23089
2025-01-28 09:49 Seclists.org

Posted by Florian Weimer on Jan 28* Pete Allor: But is this really how it works these days? For example, if we use a component to render the in-program documentation (traditionally called “online hel…

Re: Node.js EOL CVEs: CVE-2025-23087, CVE-2025-23088, CVE-2025-23089
2025-01-27 23:21 Seclists.org

Posted by Pete Allor on Jan 27Florian, The question is about who is scoring and a level of their knowledge and understanding. Assuming that each is using CVSS v3.1 then the question is does the scori…

Re: Node.js EOL CVEs: CVE-2025-23087, CVE-2025-23088, CVE-2025-23089
2025-01-27 06:36 Seclists.org

Posted by Florian Weimer on Jan 26* Pete Allor: The larger problem is that component scoring tends to be higher than whole-system scoring. If a security component fails in its security function, it c…

Re: Node.js EOL CVEs: CVE-2025-23087, CVE-2025-23088, CVE-2025-23089
2025-01-25 15:23 Seclists.org

Posted by Pete Allor on Jan 25Assigning a CVE for EOL is actually outside the normal practice (there is another standard for that underway) and is not in line with Rule 4.1 as part of the CVE program…