Description
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
Recommendation
Update the simplehttpserver
package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.1
- Patched version(s): 0.2.1
References
Related Issues
- Prebid-universal-creative latest on npm briefly compromised - CVE-2025-59039
- Potential XSS vulnerability in jQuery (GHSA-gxr4-xjj5-5px2) - CVE-2020-11022
- Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags - CVE-2021-33295
- Joplin Vulnerable to Cross-site Scripting in Note Content - CVE-2018-1000534
- Tags:
- npm
- simplehttpserver
Anything's wrong? Let us know Last updated on September 12, 2023