Vulnerabilities/

Directory Traversal vulnerability in serve-lite

Severity:
High

Description

All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
serve-lite
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing