VDB
Sign up
HIGH7.5

GHSA-vfp9-gwrh-wq9g

Path Traversal in crud-file-server

Quick fix

GHSA-vfp9-gwrh-wq9g — crud-file-server: upgrade to the fixed version with the command below.

npm install crud-file-server@0.9.0

Details

Versions of `crud-file-server` prior to 0.9.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.

## Recommendation

Upgrade to version 0.9.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/crud-file-server
Introduced in: 0Fixed in: 0.9.0
Fixnpm install crud-file-server@0.9.0

References