Executive brief
st is a Node.js module for serving static files with caching and HTTP features. Versions before 0.2.5 fail to properly decode URL-encoded dots (%2e), allowing attackers on the network to bypass path restrictions and read sensitive files directly from the server's filesystem.
Technical details
This is a directory traversal vulnerability (CWE-22) in st's URL path handling. The root cause is improper canonicalization of URL-encoded input: the module fails to decode %2e sequences before validating paths, allowing an attacker to craft requests like /%2e/%2e/etc/passwd that traverse the intended document root. The vulnerability requires only network access and a GET request—no authentication or user interaction is necessary. An unauthenticated remote attacker can read arbitrary files served by the application with the permissions of the st process. The fix is to upgrade to version 0.2.5 or later, which properly normalizes URL-encoded paths before path validation.
Affected products
- isaacs st < 0.2.5
Timeline
- 2014-05: disclosed: Disclosed on oss-security mailing list
- 2014: patched: Fixed in version 0.2.5
- 2020-08-31: advisory: GitHub Security Advisory published