Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as ../ to read files outside of the served directory.