Executive brief
serveryztyzt is an npm package used to serve files over HTTP. The package fails to properly validate file path requests, allowing attackers to access files outside the intended directory root through relative path manipulation (e.g., ../ sequences). An attacker can read sensitive files like /etc/passwd, exposing private system or application data without authentication.
Technical details
The vulnerability is a classic directory traversal (CWE-22) caused by inadequate path normalization in the file serving logic. The affected package does not properly resolve or sanitize relative file paths, allowing an attacker to construct HTTP GET requests with traversal sequences (../) to access files outside the intended root directory. The attack is network-accessible, requires no authentication or user interaction, and can lead to unauthorized disclosure of arbitrary files readable by the process. No patch is available; the vendor recommends this package be used only for local development.
Affected products
- npm serveryztyzt
Timeline
- 2020-09-01: disclosed