Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler
- Severity:
- Medium
Description
Missing check vulnerability in the static file handler allows any client to access the files in the server’s file system
Recommendation
Update the @graphql-mesh/http package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.19
- Patched version(s): 0.3.19
References
Related Issues
- @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtrac - CVE-2025-25290
- @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Back - CVE-2025-25288
- docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token - CVE-2025-53624
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
You might also like:
- Tags:
- npm
- @graphql-mesh/http
Anything's wrong? Let us know Last updated on February 20, 2025


