GHSA-5g97-whc9-8g7j
HIGHCVE-2023-26111node-static and its fork, @nubosoftware/node-static, are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
- Affected
- <= 0.7.11
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2023-03-06
- Source
- github