With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers
but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://hackerone.com/reports/2575105 |
![]() ![]() |
History
Tue, 11 Feb 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
ssvc
|
Wed, 22 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23. | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: hackerone
Published: 2025-01-22T01:11:30.802Z
Updated: 2025-02-10T23:13:08.999Z
Reserved: 2025-01-10T19:05:52.772Z
Link: CVE-2025-23090

Updated: 2025-02-10T23:13:03.280Z

Status : Awaiting Analysis
Published: 2025-01-22T02:15:34.443
Modified: 2025-02-11T00:15:29.570
Link: CVE-2025-23090

No data.