VDB
Sign up
HIGH7.5

GHSA-5g97-whc9-8g7j

node-static and @nubosoftware/node-static vulnerable to Directory Traversal

Details

node-static and its fork, @nubosoftware/node-static, are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-static
Introduced in: 0

No fixed version published yet for node-static (npm). Pin to a known-safe version or switch to an alternative.

npm/@nubosoftware/node-static
Introduced in: 0

No fixed version published yet for @nubosoftware/node-static (npm). Pin to a known-safe version or switch to an alternative.

References