This vulnerability affects Windows users of `path.join` API.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21939 | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 05 Nov 2025 07:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 24 Jul 2025 05:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodejs
Nodejs nodejs |
|
| Vendors & Products |
Nodejs
Nodejs nodejs |
Tue, 22 Jul 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Sat, 19 Jul 2025 08:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-11-04T21:09:47.526Z
Reserved: 2025-02-20T01:00:01.798Z
Link: CVE-2025-27210
Updated: 2025-11-04T21:09:47.526Z
Status : Awaiting Analysis
Published: 2025-07-18T23:15:23.343
Modified: 2025-11-04T22:16:08.123
Link: CVE-2025-27210
No data.
OpenCVE Enrichment
Updated: 2025-07-24T05:19:28Z
EUVD