HIGH7.5
GHSA-2gjg-5x33-mmp2
Path Traversal in localhost-now
Quick fix
GHSA-2gjg-5x33-mmp2 — localhost-now: upgrade to the fixed version with the command below.
npm install localhost-now@1.0.2Details
Versions of `localhost-now` before 1.0.2 are vulnerable to path traversal. This allows a remote attacker to read the content of an arbitrary file.
## Recommendation
Update to version 1.0.2 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3729[ADVISORY]
- https://github.com/DCKT/localhost-now/commit/30b004c7f145d677df8800a106c2edc982313995#diff-b9cfc7f2cdf78a7f4b91a753d10865a2[WEB]
- https://hackerone.com/reports/312889[WEB]
- https://github.com/advisories/GHSA-2gjg-5x33-mmp2[ADVISORY]
- https://www.npmjs.com/advisories/582[WEB]