CVE-2025-27210
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
18/07/2025
Last modified:
22/07/2025
Description
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. <br />
<br />
This vulnerability affects Windows users of `path.join` API.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH