Versions of serve
prior to 7.0.1 are vulnerable to Path Traversal. Explicitly ignored folders can be accessed through if the path contains a /./
, which allows attackers to access hidden folders and files.
Upgrade to version 7.0.1 or later.
{ "nvd_published_at": null, "cwe_ids": [ "CWE-548" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:56:44Z" }