Description
Versions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded ../.
Recommendation
Update the sapper package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.27.11
- Patched version(s): 0.27.11
References
Related Issues
- Path Traversal in zero - Vulnerability
- mapshaper Path Traversal vulnerability - CVE-2024-1163
- liquidjs has a path traversal fallback vulnerability - CVE-2026-30952
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
You might also like:
- Tags:
- npm
- sapper
Anything's wrong? Let us know Last updated on January 09, 2023


