GHSA-cv3v-7846-6pxm

Suggest an improvement
Source
https://github.com/advisories/GHSA-cv3v-7846-6pxm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-cv3v-7846-6pxm/GHSA-cv3v-7846-6pxm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cv3v-7846-6pxm
Published
2020-09-03T21:15:19Z
Modified
2026-07-17T18:30:27Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Unauthorized File Access in node-git-server
Details

Versions of node-git-server prior to 0.6.1 are vulnerable to Unauthorized File Access. It is possible to access any git repository by using absolute paths, which may allow attackers to access private repositories.

Recommendation

Upgrade to version 0.6.1 or later.

Database specific
{
    "cwe_ids": [
        "CWE-552"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:51:11Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / node-git-server

Package

Name
node-git-server
View open source insights on deps.dev
Purl
pkg:npm/node-git-server

Affected ranges

Type
SEMVER
Events
Introduced
0.2.0
Fixed
0.6.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-cv3v-7846-6pxm/GHSA-cv3v-7846-6pxm.json"