Executive brief
serveryaozeyan is a Node.js development server package. The vulnerability allows attackers to access files outside the intended web root directory by crafting malicious requests with path traversal sequences (e.g., "../../"), potentially exposing sensitive system files and private data on affected servers.
Technical details
The vulnerability is a classic directory traversal (CWE-22) flaw in serveryaozeyan's file path resolution logic. The server fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse parent directories using "../" sequences. The attack requires network access to the server and no authentication; an attacker can craft a GET request like "GET /../../../../../../etc/passwd" to read arbitrary files. This results in confidentiality impact through unauthorized file disclosure. No patch is available; the advisory recommends using the package only for local development and switching to alternatives if production deployment is required.
Affected products
- npm serveryaozeyan all versions
Timeline
- 2020-09-01: disclosed