Description
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0884 | node-static and @nubosoftware/node-static vulnerable to Directory Traversal |
Github GHSA |
GHSA-5g97-whc9-8g7j | node-static and @nubosoftware/node-static vulnerable to Directory Traversal |
References
History
Wed, 05 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-03-05T20:30:05.472Z
Reserved: 2023-02-20T10:28:48.922Z
Link: CVE-2023-26111
Updated: 2024-08-02T11:39:06.577Z
Status : Modified
Published: 2023-03-06T05:15:12.920
Modified: 2025-03-05T21:15:18.010
Link: CVE-2023-26111
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA