An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
https://github.com/mindeddu/Vulnerable-CVE-2025-27210
https://github.com/B1ack4sh/Blackash-CVE-2025-27210
https://nodejs.org/en/blog/vulnerability/july-2025-security-releases