VDB
Sign up
MEDIUM

GHSA-rv49-54qp-fw42

Path Traversal in servey

Quick fix

GHSA-rv49-54qp-fw42 — servey: upgrade to the fixed version with the command below.

npm install servey@3.1.0

Details

Versions of `servey` prior to 3.x are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths.

## Recommendation

Upgrade to the latest version

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/servey
Introduced in: 0Fixed in: 3.1.0
Fixnpm install servey@3.1.0

References