VDB
Sign up
MEDIUM

GHSA-4vvp-x9h2-x2vf

Path Traversal in public

Details

All versions of `public` are vulnerable to Path Traversal. This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.

## Recommendation

No fix is currently available. Do not use `public` in production or consider using an alternative module until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/public
Introduced in: 0.0.0

No fixed version published yet for public (npm). Pin to a known-safe version or switch to an alternative.

References