CVE-2023-26111, GHSA-5g97-whc9-8g7j
npm/@nubosoftware/node-static
node-static and @nubosoftware/node-static vulnerable to Directory Traversal
All versions of the package @nubosoftware/node-static; all versions of the package node-static is vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
All versions up to 0.7.11
Unfortunately, there is no solution available yet.
2023-03-08
source |