Description
Versions of zero prior to 1.0.6 are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using relative paths when fetching files.
Recommendation
Update the zero package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.6
- Patched version(s): 1.0.6
References
Related Issues
- Flowise: Path Traversal in Vector Store basePath - Vulnerability
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858
- Path traversal for local publishers in TechDocs backend - Vulnerability
You might also like:
- Tags:
- npm
- zero
Anything's wrong? Let us know Last updated on January 09, 2023


