VDB
Sign up
MEDIUM

GHSA-vc6r-4x6g-mmqc

Path Traversal in m-server

Quick fix

GHSA-vc6r-4x6g-mmqc — m-server: upgrade to the fixed version with the command below.

npm install m-server@1.4.2

Details

Versions of `m-server` before 1.4.2 are vulnerable to path traversal allowing a remote attacker to display content of arbitrary files from the server.

## Recommendation

Update to version 1.4.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/m-server
Introduced in: 0Fixed in: 1.4.2
Fixnpm install m-server@1.4.2

References