Description
Versions of zero prior to 1.0.6 are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using relative paths when fetching files.
Recommendation
Update the zero package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.6
- Patched version(s): 1.0.6
References
Could your website be exposed too?
SmartScanner can check your website for Path Traversal in zero and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: Path Traversal in Vector Store basePath - Vulnerability
- MCPHub has Path Traversal via Malicious MCPB Manifest Name - Vulnerability
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858
- Path traversal for local publishers in TechDocs backend - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


