Description
Versions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded ../.
Recommendation
Update the sapper package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.27.11
- Patched version(s): 0.27.11
References
Could your website be exposed too?
SmartScanner can check your website for Path Traversal in sapper and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Path Traversal in zero - Vulnerability
- mapshaper Path Traversal vulnerability - CVE-2024-1163
- liquidjs has a path traversal fallback vulnerability - CVE-2026-30952
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


