All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2025-03-05T20:30:05.472Z

Reserved: 2023-02-20T10:28:48.922Z

Link: CVE-2023-26111

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.577Z

cve-icon NVD

Status : Modified

Published: 2023-03-06T05:15:12.920

Modified: 2025-03-05T21:15:18.010

Link: CVE-2023-26111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.