MEDIUM
GHSA-4vvp-x9h2-x2vf
Path Traversal in public
Details
All versions of `public` are vulnerable to Path Traversal. This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.
## Recommendation
No fix is currently available. Do not use `public` in production or consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/public
Introduced in:
0.0.0No fixed version published yet for public (npm). Pin to a known-safe version or switch to an alternative.