HIGH7.5
GHSA-cxmj-qjv6-vx9p
mcstatic directory traversal vulnerability
Details
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/mcstatic
Introduced in:
0No fixed version published yet for mcstatic (npm). Pin to a known-safe version or switch to an alternative.