Junglewise Threat Intelligence

CVE-2017-16104: citypredict.whauwiller directory traversal

CVE-2017-16104 · Severity: low · CVSS 3 · Published 2018-07-24

Vendors: npm.

Executive brief

citypredict.whauwiller is an npm library that resolves relative file paths without proper validation. An attacker can exploit this vulnerability to access files outside the intended directory root, potentially exposing sensitive system files such as configuration files or private data stored on the server.

Technical details

The vulnerability is a classic directory traversal (CWE-22) flaw in which the library resolves relative file paths without proper validation or sandboxing. An unauthenticated, remote attacker can craft HTTP requests containing path traversal sequences (e.g., "../../../../../../etc/passwd") to access files outside the intended directory root. No user interaction is required, and the vulnerability is network-accessible if the application using this library is exposed. No patch has been released; the recommendation is to use the package only for local development and switch to an alternative package for production use.

Affected products

  • whauwiller citypredict.whauwiller all versions up to and including 1.0.0

Timeline

  • 2018-07-24: disclosed: Advisory published

References