Vulnerabilities/

Path Traversal in node-red-contrib-huemagic

Severity:
High

Description

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
node-red-contrib-huemagic
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing