CVE-2025-27210 | Node.js up to 20.19.3/22.17.0/24.4.0 Windows Device Name path traversal (EUVD-2025-21939 / EDB-52369)
A vulnerability, which was classified as problematic, was found in Node.js up to 20.19.3/22.17.0/24.4.0. Impacted is an unknown function of the component Windows Device Name Handler. Executing manipulation can lead to path traversal.
This vulnerability appears as CVE-2025-27210. The attack may be performed from remote. In addition, an exploit is available.
You should upgrade the affected component.