Executive brief
cyber-js is a JavaScript library used for file serving and web development. The vulnerability allows attackers to bypass directory restrictions and access sensitive files (such as /etc/passwd) on the system by using relative path traversal sequences. No patch is available; the vendor recommends using the package only for local development.
Technical details
cyber-js contains a directory traversal vulnerability (CWE-22) in its file path resolution logic. The vulnerability occurs because the library does not properly sanitize or validate relative file paths (e.g., ../../etc/passwd), allowing traversal outside the intended root directory. The attack is unauthenticated and requires only network access to a server running the vulnerable library; no user interaction is needed. An attacker can read arbitrary files accessible to the web server process, potentially exposing sensitive application or system files. No patch has been released; the only mitigation is to discontinue use of the package in production environments.
Affected products
- cyber-js cyber-js ≤1.0.7
Timeline
- 2018-07-27: disclosed