Junglewise Threat Intelligence

algo-httpserv path traversal vulnerability

Severity: low · CVSS 3.1 · Published 2019-09-11

Vendors: Unknown, npm.

Executive brief

algo-httpserv is a lightweight HTTP server library used to serve files and handle web requests. Versions before 1.1.2 contain a path traversal flaw that allows attackers to read arbitrary files from the server by manipulating file paths with directory traversal sequences, potentially exposing sensitive configuration files, application source code, and system credentials.

Technical details

The vulnerability is a path traversal (CWE-22) caused by insufficient input sanitization in the HTTP request handler. Attackers can exploit this remotely without authentication by crafting requests with relative path sequences (e.g., "../") or URL-encoded variants (e.g., "%2e%2e/") to escape the intended file serving directory and access arbitrary files on the server filesystem. The attack requires no special privileges or user interaction, and successful exploitation results in unauthorized information disclosure of sensitive files. The vulnerability was fixed in version 1.1.2 by adding proper path validation.

Affected products

  • <unknown> algo-httpserv prior to 1.1.2

Timeline

  • 2019-05-17: disclosed
  • 2019-09-03: patched: Version 1.1.2 released with fix
  • 2019-09-11: advisory

References