VDB
Sign up
LOW

GHSA-m33v-338h-4v9f

Path traversal in Node-Red

Quick fix

GHSA-m33v-338h-4v9f — @node-red/runtime: upgrade to the fixed version with the command below.

npm install @node-red/runtime@1.2.8

Details

### Impact

This vulnerability allows arbitrary path traversal via the Projects API.

If the Projects feature is enabled, a user with `projects.read` permission is able to access any file via the Projects API.

### Patches

The issue has been patched in Node-RED 1.2.8

### Workarounds

The vulnerability applies only to the Projects feature which is not enabled by default in Node-RED.

The primary workaround is not give untrusted users read access to the Node-RED editor.

### For more information If you have any questions or comments about this advisory: * Email us at [team@nodered.org](mailto:team@nodered.org)

### Acknowledgements

Thanks to the Tencent Woodpecker Security Team for disclosing this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@node-red/runtime
Introduced in: 0Fixed in: 1.2.8
Fixnpm install @node-red/runtime@1.2.8

References