Description
All versions of localhost-now are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.2
References
Related Issues
- Path Traversal in localhost-now - CVE-2019-5416
- Path Traversal in localhost-now - localhost-now - GHSA-2gjg-5x33-mmp2 - CVE-2018-3729
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
You might also like:
- Tags:
- npm
- localhost-now
Anything's wrong? Let us know Last updated on January 09, 2023


