GHSA-3p34-w4f6-5xh2: better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
A directory traversal vulnerability exists in the production static file server of better-helperjs (<= 3.0.5). Attackers can read arbitrary files located in adjacent directory structures that share the same string prefix as the intended static root directory.
References
Code Behaviors & Features
Detect and mitigate GHSA-3p34-w4f6-5xh2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →