Description
Versions of ponse prior to 2.0.2 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.
Recommendation
Update the ponse package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.2
- Patched version(s): 2.0.2
References
Could your website be exposed too?
SmartScanner can check your website for Path Traversal in ponse and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Path Traversal in sapper - Vulnerability
- Jan path traversal vulnerability - CVE-2024-37273
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


