Versions of node-git-server prior to 0.6.1 are vulnerable to Unauthorized File Access. It is possible to access any git repository by using absolute paths, which may allow attackers to access private repositories.
Upgrade to version 0.6.1 or later.
{
"cwe_ids": [
"CWE-552"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:51:11Z",
"nvd_published_at": null,
"severity": "HIGH"
}