HIGH7.5
GHSA-x2jc-989c-47q4
Hexo `include_code` has a path traversal
Quick fix
GHSA-x2jc-989c-47q4 — hexo: upgrade to the fixed version with the command below.
npm install hexo@7.2.0Details
Hexo up to v7.1.1 was discovered to contain an arbitrary file read vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-39584[ADVISORY]
- https://github.com/hexojs/hexo/issues/5250[WEB]
- https://github.com/hexojs/hexo/pull/5251[WEB]
- https://github.com/hexojs/hexo/commit/b5b63caee27256d71a0cee8954c22375ec885d07[WEB]
- https://github.com/hexojs/hexo[PACKAGE]
- https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49[WEB]
- https://github.com/hexojs/hexo/blob/cefee921153ba597316457f4fedf7b87b6516917/lib/plugins/tag/include_code.ts#L50[WEB]