Executive brief
commentapp.stetsonwood is a Node.js package that resolves relative file paths without proper validation. An attacker can craft malicious URLs with directory traversal sequences (like ../../) to read arbitrary files from the server, such as sensitive configuration or source code files. This vulnerability could expose passwords, API keys, or other confidential data stored on the server.
Technical details
commentapp.stetsonwood contains a path traversal vulnerability (CWE-22) in its file path resolution logic. The package fails to sanitize user-supplied file paths, allowing attackers to traverse the directory hierarchy using sequences like ../../. An unauthenticated network-based attacker can craft GET requests with directory traversal payloads (e.g., GET /../../../../../../etc/passwd) to read arbitrary files outside the intended directory root. The vulnerability has no available patch; the package is deprecated and only recommended for local development use.
Affected products
- npm commentapp.stetsonwood 0.0.1 and earlier
Timeline
- 2018-07-23: disclosed
- 2017: other: CVE-2017-16143 assigned