VDB
Sign up
HIGH7.5

GHSA-xg75-3277-gvvj

Directory Traversal in serve

Quick fix

GHSA-xg75-3277-gvvj — serve: upgrade to the fixed version with the command below.

npm install serve@7.1.3

Details

Versions of `serve` before 7.1.3 are vulnerable to Directory Traversal. File paths are not sanitized leading to unauthorized access of system files.

## Recommendation

Upgrade to version 7.1.3 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/serve
Introduced in: 0Fixed in: 7.1.3
Fixnpm install serve@7.1.3

References