Junglewise Threat Intelligence

CVE-2017-16103: serveryztyzt directory traversal

CVE-2017-16103 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

serveryztyzt is an npm package used to serve files over HTTP. The package fails to properly validate file path requests, allowing attackers to access files outside the intended directory root through relative path manipulation (e.g., ../ sequences). An attacker can read sensitive files like /etc/passwd, exposing private system or application data without authentication.

Technical details

The vulnerability is a classic directory traversal (CWE-22) caused by inadequate path normalization in the file serving logic. The affected package does not properly resolve or sanitize relative file paths, allowing an attacker to construct HTTP GET requests with traversal sequences (../) to access files outside the intended root directory. The attack is network-accessible, requires no authentication or user interaction, and can lead to unauthorized disclosure of arbitrary files readable by the process. No patch is available; the vendor recommends this package be used only for local development.

Affected products

  • npm serveryztyzt

Timeline

  • 2020-09-01: disclosed

References