Versions of serve prior to 7.0.1 are vulnerable to Path Traversal. Explicitly ignored folders can be accessed through if the path contains a /./, which allows attackers to access hidden folders and files.
Upgrade to version 7.0.1 or later.
{
"severity": "HIGH",
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:56:44Z",
"cwe_ids": [
"CWE-548"
],
"github_reviewed": true
}