Post

2026-01-22 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-55130nodejs - nodeA flaw in Node.js’s Permissions model allows attackers to bypass `–allow-fs-read` and `–allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.0Exploitation: noneAutomatable: noTechnical Impact: totalundefinedgithub 
CVE-2025-13465Lodash - LodashLodash-amd - Lodash-amdlodash-es - lodash-eslodash.unset - lodash.unsetLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23CVSS4.0: 6.9 - MEDIUM0Exploitation: noneAutomatable: yesTechnical Impact: partialPrototype Pollution Vulnerability in Lodash _.unset and _.omit functionsgithub
This post is licensed under CC BY 4.0 by the author.