CVE-2025-23083

Public on 2025-01-22
Modified on 2025-01-23
Description
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.

This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Severity
Important severity
Important
CVSS v3 Base Score
7.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2023 nodejs Not Affected
HAQM Linux 2023 nodejs20 2025-01-30 ALAS2023-2025-822 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NVD CVSSv3 7.7 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N