Disclosure summary
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Source-reported weakness categories
CWE-284
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2025-Jan
Open original source · Updated Feb 17, 2026
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 7.7
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | azl3 nodejs 20.14.0-8 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 nodejs 20.14.0-4 on Azure Linux 3.0 | (MSRC status code 3) |
Vendor remediation references
- CBL-Mariner Releases · build 20.14.0-4 · product IDs 19608-17084, 19353-17084
- Vendor guidance · product IDs 19608-17084, 19353-17084
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2025-01-31T19:00:00-05:00
MODIFIED 2026-02-17T21:34:11-05:00
INGESTED 2026-10-08T12:50:16-04:00