VDB
Sign up
HIGH7.5

GHSA-x26f-26qw-hhhx

Path Traversal in hekto

Quick fix

GHSA-x26f-26qw-hhhx — hekto: upgrade to the fixed version with the command below.

npm install hekto@0.2.3

Details

Versions of `hekto` before 0.2.3 are vulnerable to path traversal. This allows a remote attacker to read content of arbitrary files.

## Recommendation

Update to version 0.2.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hekto
Introduced in: 0Fixed in: 0.2.3
Fixnpm install hekto@0.2.3

References