Description
Versions of localhost-now before 1.0.2 are vulnerable to path traversal. This allows a remote attacker to read the content of an arbitrary file.
Recommendation
Update the localhost-now package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.2
- Patched version(s): 1.0.2
References
Could your website be exposed too?
SmartScanner can check your website for Path Traversal in localhost-now - localhost-now - GHSA-2gjg-5x33-mmp2 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Path Traversal in localhost-now - CVE-2019-5416
- Path Traversal in localhost-now - localhost-now - Vulnerability
- Jan path traversal vulnerability - @janhq/core - GHSA-5jqc-qj57-4hrc - CVE-2024-36857
- Path Traversal in mcstatic - CVE-2018-3730
You might also like:
See something that needs correcting? Let us knowUpdated March 01, 2023


