HIGH7.5
GHSA-5g97-whc9-8g7j
node-static and @nubosoftware/node-static vulnerable to Directory Traversal
Details
node-static and its fork, @nubosoftware/node-static, are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/node-static
Introduced in:
0No fixed version published yet for node-static (npm). Pin to a known-safe version or switch to an alternative.
npm/@nubosoftware/node-static
Introduced in:
0No fixed version published yet for @nubosoftware/node-static (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-26111[ADVISORY]
- https://gist.github.com/lirantal/c80b28e7bee148dc287339cb483e42bc[WEB]
- https://github.com/cloudhead/node-static[PACKAGE]
- https://github.com/cloudhead/node-static/blob/master/lib/node-static.js#23L160-L163[WEB]
- https://security.snyk.io/vuln/SNYK-JS-NODESTATIC-3149928[WEB]
- https://security.snyk.io/vuln/SNYK-JS-NUBOSOFTWARENODESTATIC-3149927[WEB]