VDB
Sign up
MEDIUM5.3

GHSA-6fmm-47qc-p4m4

Unauthorized File Access in harp

Quick fix

GHSA-6fmm-47qc-p4m4 — harp: upgrade to the fixed version with the command below.

npm install harp@0.40.3

Details

All versions of `harp` are vulnerable to Unauthorized File Access. If a symlink in the project's base directory points to a file outside of the directory, the file is served. This could allow an attacker to access sensitive files on the server.

## Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/harp
Introduced in: 0Fixed in: 0.40.3
Fixnpm install harp@0.40.3

References