Lack of data validation - Path Traversal In @nubosoftware/node-static
Description
node-static and @nubosoftware/node-static vulnerable to Directory Traversal node-static and its fork, @nubosoftware/node-static, are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
npm | ||
npm |
Aliases
1. 2. 3. 4.
References
1. 2.