A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via futimes() even when the process has only read permissions. Unlike utimes(), futimes() does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. Impact: Thank you, to oriotie for reporting this vulnerability and thank you RafaelGSS for fixing it.
https://nodejs.org/en/blog/vulnerability/december-2025-security-releases