#VU126392 Improper access control in Node.js - CVE-2025-55132
Published: April 17, 2026
Node.js
Node.js Foundation
Description
The vulnerability allows a local user to modify file timestamps.
The vulnerability exists due to improper access control in fs.futimes() when changing file timestamps without expected write-permission checks. A local user can call futimes() to modify file timestamps.
This can reduce the reliability of logs by obscuring activity in read-only directories.