GHSA-frpw-jrwx-hcfv
HIGHCVE-2021-25864node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
- Affected
- <= 3.0.0
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2021-04-13
- Source
- github