Description
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath
function of server.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.2.1
References
Related Issues
- parse is vulnerable to prototype pollution - CVE-2025-57324
- Denial of service in http-proxy-middleware - CVE-2024-21536
- node-browser downloads Resources over HTTP - CVE-2016-10618
- chromedriver Downloads Resources over HTTP - CVE-2016-10579
- Tags:
- npm
- static-server
Anything's wrong? Let us know Last updated on September 26, 2025