Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-7fxm-c848-89q8: static-dev-server vulnerable to path traversal

This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory. There is currently no known workaround or fix for this issue.

ghsa
#git

static-dev-server vulnerable to path traversal

High severity GitHub Reviewed Published Nov 29, 2022 • Updated Dec 2, 2022

Related news

CVE-2022-25848: Snyk Vulnerability Database | Snyk

This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.