Executive brief
gaoxiaotingtingting is a Node.js package used to serve static HTML files. A directory traversal vulnerability allows attackers to access files outside the intended directory root by crafting malicious requests with path traversal sequences (e.g., ../../), potentially exposing sensitive system files like password files or private configuration data.
Technical details
This is a classic directory traversal vulnerability (CWE-22) in the gaoxiaotingtingting npm package. The package fails to properly sanitize or validate relative file paths before resolving them, allowing attackers to use path traversal sequences (e.g., ../../) in HTTP requests to navigate outside the intended web root. The vulnerability requires network access but no authentication. An attacker can read arbitrary files accessible to the application process, such as /etc/passwd or private configuration files. No patch has been released; the recommendation is to use the package only for local development and replace it with an alternative for production use.
Affected products
- npm gaoxiaotingtingting 0.0.0 and above
Timeline
- 2017: disclosed: CVE-2017-16108 assigned
- 2020-09-01: advisory: GHSA-qhf6-vqq9-q2p7 published