Impact
A path traversal flaw in cube-root/directory-serve allows an unauthenticated remote attacker to delete files located outside the intended served directory when the application is run with the "--delete" option. The flaw stems from the lack of sanitization on the req.query.file parameter, enabling traversal via "../" sequences. As a result, an attacker can remove critical files, compromise data integrity, or disrupt service availability.
Affected Systems
The affected product is cube-root:directory-serve, affecting all releases through 1.3.7. No other vendors or versions are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1, indicating a high severity level. Exploitation requires no authentication and capitalizes on easy input manipulation by an unauthenticated remote attacker. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the combination of a high CVSS score and straightforward exploitation vector suggests a notably high risk to systems running vulnerable versions.
OpenCVE Enrichment