GHSA-wm77-q74p-5763

Suggest an improvement
Source
https://github.com/advisories/GHSA-wm77-q74p-5763
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wm77-q74p-5763
Published
2018-07-27T17:06:03Z
Modified
2021-08-09T22:21:02Z
Summary
Path Traversal in superstatic
Details

Affected of superstatic are vulnerable to path traversal when used on Windows.

Additionally, it is vulnerable to path traversal on other platforms combined with certain Node.js versions which erroneously normalize \\ to / in paths on all platforms (a known example being Node.js v9.9.0).

Recommendation

Update to version 5.0.2 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-177"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T22:00:48Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / superstatic

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json"