All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
{ "nvd_published_at": "2023-10-03T05:15:50Z", "severity": "HIGH", "github_reviewed_at": "2023-10-04T14:43:33Z", "github_reviewed": true, "cwe_ids": [ "CWE-22" ] }