Description
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.2.1
References
Related Issues
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818
- Path traversal vulnerability in gatsby-plugin-sharp - CVE-2023-30548
- Path Traversal in crud-file-server - CVE-2018-3733
- Path Traversal in angular-http-server - CVE-2018-3713
- Tags:
- npm
- static-server
Anything's wrong? Let us know Last updated on September 26, 2025