Path Traversal in superstatic
High severity
GitHub Reviewed
Published
Jul 27, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Jul 27, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Affected of
superstatic
are vulnerable to path traversal when used on Windows.Additionally, it is vulnerable to path traversal on other platforms combined with certain Node.js versions which erroneously normalize
\\
to/
in paths on all platforms (a known example being Node.js v9.9.0).Recommendation
Update to version 5.0.2 or later.
References