Executive brief
serve-static is a Node.js middleware library that serves static files in web applications. When mounted at the root directory, certain browsers interpret maliciously crafted URLs as external redirects, allowing attackers to redirect users to arbitrary external websites. This can be exploited for phishing attacks or malware distribution.
Technical details
The vulnerability is an open redirect (CWE-601) in serve-static versions prior to 1.6.5 and 1.7.x prior to 1.7.2. When mounted at the root, the middleware fails to properly validate redirect locations, allowing crafted URLs with double slashes and dot-dot sequences (e.g., //www.google.com/%2e%2e) to bypass path normalization. The attack requires network access and user interaction (clicking a malicious link). Some browsers (Firefox, Safari, IE) interpret the response Location header as an external URL, redirecting users outside the application. Patches are available: update to serve-static 1.6.5 (for 1.6.x) or 1.7.2 (for 1.7.x).
Affected products
- Express.js serve-static prior to 1.6.5; 1.7.0 prior to 1.7.2
Timeline
- 2015-01-03: disclosed: Issue reported in GitHub
- 2015: patched: Fixes released in 1.6.5 and 1.7.2
- 2020-08-31: advisory: GitHub Security Advisory GHSA-c3x7-gjmx-r2ff published