Headline
GHSA-7fxm-c848-89q8: static-dev-server vulnerable to path traversal
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory. There is currently no known workaround or fix for this issue.
static-dev-server vulnerable to path traversal
High severity GitHub Reviewed Published Nov 29, 2022 • Updated Dec 2, 2022
Related news
CVE-2022-25848: Snyk Vulnerability Database | Snyk
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.