Description
Versions of ponse prior to 2.0.2 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.
Recommendation
Update the ponse package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.2
- Patched version(s): 2.0.2
References
Related Issues
- Path Traversal in sapper - Vulnerability
- Jan path traversal vulnerability - CVE-2024-37273
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
You might also like:
- Tags:
- npm
- ponse
Anything's wrong? Let us know Last updated on January 09, 2023


