GHSA-4x7w-frcq-v4m3
CRITICALAll versions of @wturyn/swagger-injector are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the configured dist folder using relative paths.
- Affected
- >= 0.0.0, >=0.0.0
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2020-09-03
- Source
- github