Description
Versions of localhost-now before 1.0.2 are vulnerable to path traversal. This allows a remote attacker to read the content of an arbitrary file.
Recommendation
Update the localhost-now package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.2
- Patched version(s): 1.0.2
References
Related Issues
- Path Traversal in localhost-now - CVE-2019-5416
- Path Traversal in localhost-now - localhost-now - Vulnerability
- Jan path traversal vulnerability - @janhq/core - GHSA-5jqc-qj57-4hrc - CVE-2024-36857
- Path Traversal in mcstatic - CVE-2018-3730
You might also like:
- Tags:
- npm
- localhost-now
Anything's wrong? Let us know Last updated on March 01, 2023


