Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wcwm-c3mr-pxcr: easy-static-server vulnerable to Directory Traversal

All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

ghsa
#git

easy-static-server vulnerable to Directory Traversal

High severity GitHub Reviewed Published Dec 20, 2022 • Updated Dec 20, 2022

Related news

CVE-2022-25931: Snyk Vulnerability Database | Snyk

All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.