Vulnerabilities/

Path Traversal in zero

Severity:
High

Description

Versions of zero prior to 1.0.6 are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using relative paths when fetching files.

Recommendation

Update the zero package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
zero
Anything's wrong? Let us know Last updated on January 09, 2023