Executive brief
infraserver is a Node.js package used to serve static files locally during development. A directory traversal flaw allows attackers to read arbitrary files on the system by crafting requests with path traversal sequences (e.g., `/../../../etc/passwd`), potentially exposing sensitive configuration files, credentials, or private data without authentication.
Technical details
The vulnerability is a classic directory traversal (CWE-22) in path resolution logic. infraserver fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse outside the intended document root using sequences like `../`. An unauthenticated, network-accessible attacker can send a specially crafted GET request to read arbitrary files readable by the process. No patch is available; the vendor recommends restricting use to local development only.
Affected products
- npm infraserver 0.0.1 and earlier
Timeline
- 2018-07-23: disclosed