Executive brief
lab6drewfusbyu is an npm package that resolves file paths, commonly used in development environments. The package fails to properly sanitize relative path sequences (like "../"), allowing attackers to access files outside the intended directory—such as system configuration files and private data—by crafting specially formed requests.
Technical details
The vulnerability is a directory traversal (CWE-22) in path resolution logic within lab6drewfusbyu. The root cause is inadequate validation of relative file paths, allowing sequences like "../../" to escape the intended directory root. The attack vector is network-based with no authentication or user interaction required. An attacker can read arbitrary files on the system by embedding traversal sequences in HTTP requests (e.g., GET /../../../../../../etc/passwd). No patch is available; the advisory recommends restricting use to local development only.
Affected products
- npm lab6drewfusbyu 0.1.1 and earlier
Timeline
- 2018-07-23: disclosed