BIT-node-min-2025-55132

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/node-min/BIT-node-min-2025-55132.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-node-min-2025-55132
Aliases
Published
2026-01-26T14:47:53.448Z
Modified
2026-02-04T10:30:16.788098Z
Summary
[none]
Details

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via futimes() even when the process has only read permissions. Unlike utimes(), futimes() does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / node-min

Package

Name
node-min
Purl
pkg:bitnami/node-min

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0
Fixed
20.20.0
Introduced
21.0.0
Fixed
22.22.0
Introduced
23.0.0
Fixed
24.13.0
Introduced
25.0.0
Fixed
25.3.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/node-min/BIT-node-min-2025-55132.json"