https://seclists.org/oss-sec/2026/q1/59: NodeJS Security leases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others)
Published Jan 13, 2026
·Updated
Affected Software
1 affected component
npm/node>=20.x<=25.x
Frequently Asked Questions
1
What is the severity of CVE-2025-55131?
CVE-2025-55131 is rated as high severity due to its potential for remote code execution.
2
How do I fix CVE-2025-55131?
To fix CVE-2025-55131, upgrade to the latest version of Node.js that addresses this vulnerability.
3
What does CVE-2025-55130 impact?
CVE-2025-55130 affects the npm package manager and can compromise package integrity.
4
Is there a workaround for CVE-2025-59465?
Currently, the recommended approach for CVE-2025-59465 is to update to a secured version of the affected software.
5
When was CVE-2025-55131 published?
CVE-2025-55131 was published on January 13, 2026.