#VU18922 Path traversal in serve-here.js
Published: June 27, 2019 / Updated: June 28, 2019
serve-here.js
npm Inc.
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the package accepts pathname of URLs and adds it to the web root without sanitization. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
PoC:
http://[host]/../../../../etc/passswd