VDB
Sign up
HIGH7.5

GHSA-rwv8-jvff-jq28

Path Traversal in public

Quick fix

GHSA-rwv8-jvff-jq28 — public: upgrade to the fixed version with the command below.

npm install public@0.1.3

Details

Versions of `public` before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user.

## Recommendation

Update to version 0.1.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/public
Introduced in: 0Fixed in: 0.1.3
Fixnpm install public@0.1.3

References