CVE-2025-23090 Details
Description
Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.
A vulnerability exists in Node.js versions 20, 22, and 23 for users with the Permission Model enabled. By using the diagnostics_channel utility, it is possible to intercept events when a worker thread is created. This not only applies to regular worker threads but also reveals internal workers, allowing an instance to be accessed. The constructor of this internal worker can be extracted and reused for malicious purposes, effectively bypassing the permission model restrictions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 18, 2025 | CVE Rejected | [email protected] |
| Jul 18, 2025 | CVE Modified | [email protected] |
| Feb 11, 2025 | CVE Modified | CISA-ADP |
| Jan 22, 2025 | New CVE Received | [email protected] |