Vulnerabilities/

Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler

Severity:
Medium

Description

Missing check vulnerability in the static file handler allows any client to access the files in the server’s file system

Recommendation

Update the @graphql-mesh/http package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@graphql-mesh/http
Anything's wrong? Let us know Last updated on February 20, 2025