Vulnerabilities/

Path Traversal in sapper

Severity:
High

Description

Versions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded ../.

Recommendation

Update the sapper package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sapper
Anything's wrong? Let us know Last updated on January 09, 2023