MEDIUM
GHSA-j27j-4w6m-8fc4
Path Traversal in statics-server
Details
All versions of `statics-server` are vulnerable to Path Traversal. The package fails to limit access to files outside of the served folder through symlinks.
## Recommendation
No fix is currently available. Do not use `statics-server` in production or consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/statics-server
Introduced in:
0No fixed version published yet for statics-server (npm). Pin to a known-safe version or switch to an alternative.