VDB
Sign up
MEDIUM5.3

GHSA-vwr2-wj63-86gr

Path Traversal in simplehttpserver

Details

All versions of `simplehttpserver` are vulnerable to Path Traversal.

This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.

## Recommendation

No fix is currently available. Do not use `simplehttpserver` in production or consider using an alternative module until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simplehttpserver
Introduced in: 0

No fixed version published yet for simplehttpserver (npm). Pin to a known-safe version or switch to an alternative.

References