Executive brief
goserv is a simple HTTP file server often used during local development. A directory traversal vulnerability allows attackers to access arbitrary files on the server by using path traversal sequences (like ../../), potentially exposing sensitive system files and application data.
Technical details
The vulnerability is a classic directory traversal (CWE-22) where goserv fails to properly sanitize relative file paths in HTTP requests. An attacker can craft requests with sequences like /../ to escape the intended document root and read arbitrary files accessible to the server process. The attack requires only network access with no authentication or user interaction needed. An attacker can achieve arbitrary file disclosure. No patch has been released; the vendor recommends using the package only for local development and switching to alternative packages for production use.
Affected products
- npm goserv through 1.0.0
Timeline
- 2018-07-23: disclosed