Junglewise Threat Intelligence

CVE-2017-16093: cyber-js directory traversal

CVE-2017-16093 · Severity: low · CVSS 3 · Published 2018-07-27

Vendors: npm.

Executive brief

cyber-js is a JavaScript library used for file serving and web development. The vulnerability allows attackers to bypass directory restrictions and access sensitive files (such as /etc/passwd) on the system by using relative path traversal sequences. No patch is available; the vendor recommends using the package only for local development.

Technical details

cyber-js contains a directory traversal vulnerability (CWE-22) in its file path resolution logic. The vulnerability occurs because the library does not properly sanitize or validate relative file paths (e.g., ../../etc/passwd), allowing traversal outside the intended root directory. The attack is unauthenticated and requires only network access to a server running the vulnerable library; no user interaction is needed. An attacker can read arbitrary files accessible to the web server process, potentially exposing sensitive application or system files. No patch has been released; the only mitigation is to discontinue use of the package in production environments.

Affected products

  • cyber-js cyber-js ≤1.0.7

Timeline

  • 2018-07-27: disclosed

References