VDB
Sign up
LOW3.1

GHSA-c3x7-gjmx-r2ff

Open Redirect in serve-static

Quick fix

GHSA-c3x7-gjmx-r2ff — serve-static: upgrade to the fixed version with the command below.

npm install serve-static@1.7.2

Details

Versions of `serve-static` prior to 1.6.5 ( or 1.7.x prior to 1.7.2 ) are affected by an open redirect vulnerability on some browsers when configured to mount at the root directory.

## Proof of Concept

A link to `http://example.com//www.google.com/%2e%2e` will redirect to `//www.google.com/%2e%2e`

Some browsers will interpret this as `http://www.google.com/%2e%2e`, resulting in an external redirect.

## Recommendation

Version 1.7.x: Update to version 1.7.2 or later. Version 1.6.x: Update to version 1.6.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/serve-static
Introduced in: 0Fixed in: 1.7.2
Fixnpm install serve-static@1.7.2
npm/serve-static
Introduced in: 1.7.0Fixed in: 1.7.2
Fixnpm install serve-static@1.7.2

References