With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
References
History

Tue, 11 Feb 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
References
Metrics cvssV3_0

{'score': 7.7, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2025-01-22T01:11:30.802Z

Updated: 2025-02-10T23:13:08.999Z

Reserved: 2025-01-10T19:05:52.772Z

Link: CVE-2025-23090

cve-icon Vulnrichment

Updated: 2025-02-10T23:13:03.280Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-22T02:15:34.443

Modified: 2025-02-11T00:15:29.570

Link: CVE-2025-23090

cve-icon Redhat

No data.