Path Traversal in statics-server
Moderate severity
GitHub Reviewed
Published
Mar 31, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Mar 31, 2020
Published to the GitHub Advisory Database
Mar 31, 2020
Last updated
Jan 9, 2023
All versions of
statics-server
are vulnerable to Path Traversal. The package fails to limit access to files outside of the served folder through symlinks.Recommendation
No fix is currently available. Do not use
statics-server
in production or consider using an alternative module until a fix is made available.References