Vulnerabilities/

Directory Traversal in @vivaxy/here

Severity:
High

Description

The @vivaxy/here module is a small web server that serves files with the process’ working directory acting as the web root.

It is vulnerable to a directory traversal attack.

This means that files on the local file system which exist outside of the web root may be disclosed to an attacker. This might include confidential files.

Recommendation

Update the @vivaxy/here package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@vivaxy/here
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing