Description
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F
Directory Traversal.in the res.sendFile
API, used in file hue-magic.js, to fetch an arbitrary file.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.0.0
References
Related Issues
- mpregular vulnerable to prototype pollution - CVE-2025-57323
- DOMPurify allows Cross-site Scripting (XSS) - CVE-2025-26791
- lite-server vulnerable to Denial of Service - CVE-2022-25940
- Manifest Uses a One-Way Hash without a Salt - CVE-2025-27408
- Tags:
- npm
- node-red-contrib-huemagic
Anything's wrong? Let us know Last updated on September 07, 2023