VDB
Sign up
HIGH7.5

GHSA-69rr-wvh9-6c4q

Directory Traversal in st

Quick fix

GHSA-69rr-wvh9-6c4q — st: upgrade to the fixed version with the command below.

npm install st@0.2.5

Details

Versions of `st` prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused `%2e` to be interpreted as `.` by the filesystem, resulting the potential for an attacker to read sensitive files on the server.

## Recommendation

Update to version 0.2.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/st
Introduced in: 0Fixed in: 0.2.5
Fixnpm install st@0.2.5

References