VDB
Sign up
HIGH7.5

GHSA-v588-qcp3-jv46

Path Traversal in serve

Quick fix

GHSA-v588-qcp3-jv46 — serve: upgrade to the fixed version with the command below.

npm install serve@7.0.0

Details

Versions of `serve` prior to 7.0.1 are vulnerable to Path Traversal. Explicitly ignored folders can be accessed through if the path contains a `/./`, which allows attackers to access hidden folders and files.

## Recommendation

Upgrade to version 7.0.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/serve
Introduced in: 0Fixed in: 7.0.0
Fixnpm install serve@7.0.0

References