Proof of Concept CVE-2025-27210,一种精确的路径遍历漏洞,影响在 Microsoft Windows 上运行的 Node.js 应用程序。该漏洞利用了 Windows 处理保留设备文件名(例如 AUX、CON、NUL)时的特定方式,结合路径中的目录遍历序列(../),这些路径由 path.join() 或 path.normalize() 等函数处理。
python CVE-2025-27210_NodeJS_Path_Traversal_Exploiter.py -t http://localhost:3000/download -f C:\\Windows\System32\drivers\etc\hosts

.jpg)
该漏洞由以下人员报告: @theoblivionsage https://x.com/theoblivionsage | https://hackerone.com/oblivionsage