All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26152.json"