HIGH7.5
GHSA-vfp9-gwrh-wq9g
Path Traversal in crud-file-server
Quick fix
GHSA-vfp9-gwrh-wq9g — crud-file-server: upgrade to the fixed version with the command below.
npm install crud-file-server@0.9.0Details
Versions of `crud-file-server` prior to 0.9.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.
## Recommendation
Upgrade to version 0.9.0 or later.
Are you affected?
Enter the version of the package you're using.