VDB
Sign up
HIGH7.5

GHSA-cxmj-qjv6-vx9p

mcstatic directory traversal vulnerability

Details

A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mcstatic
Introduced in: 0

No fixed version published yet for mcstatic (npm). Pin to a known-safe version or switch to an alternative.

References