coursevault-preview versions prior to 0.1.1 contain a path traversal vulnerability in the resolveSafe utility. The boundary check used String.prototype.startsWith(baseDir) on a normalized path, which does not enforce a directory boundary. An attacker who controls the relativePath argument to affected CoursevaultPreview methods may be able to read files outside the configured baseDir when a sibling directory exists whose name shares the same string prefix.
The vulnerable code in src/utils/errors.ts:
if (!full.startsWith(base)) { // ← insufficient
throw new Error("Path escapes the base directory");
}
Because the check is a raw string prefix test rather than a path-boundary test, the following bypass is possible:
baseDir = "/srv/courses"
payload = "../courses-admin/config.json"
resolved = "/srv/courses-admin/config.json"
"/srv/courses-admin/config.json".startsWith("/srv/courses") // → true ✗
Any file whose absolute path begins with the baseDir string — including files in sibling directories that share a name prefix — passes the guard and can be accessed by the caller through affected file-access methods.
The fix replaces the check with a separator-aware comparison:
if (full !== base && !full.startsWith(base + sep)) {
throw new Error("Path escapes the base directory");
}
An application that passes untrusted input as the relativePath argument to affected file-access methods may expose file contents outside the intended directory.
relativePath parameter.baseDir.There is no network exposure in the package itself; impact is limited to local file disclosure within the host process's file system permissions.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-08T00:06:03Z",
"nvd_published_at": "2026-04-07T17:16:35Z",
"severity": "MODERATE"
}