Executive brief
myserver.alexcthomas18 is a Node.js package that serves files over HTTP. The package fails to properly validate file paths, allowing attackers to access files outside the intended directory tree (such as /etc/passwd) without any authentication. This could expose sensitive system files and secrets to an attacker over the network.
Technical details
The vulnerability is a path traversal (CWE-22) flaw where the package resolves relative file paths without proper normalization or bounds checking. An unauthenticated network attacker can craft HTTP GET requests using path traversal sequences (e.g., /../../../) to escape the intended root directory and read arbitrary files on the system. No authentication or user interaction is required. An attacker can disclose private files including application secrets and system configuration. No patch is available; the vendor recommends using the package only for local development or switching to an alternative.
Affected products
- alexcthomas18 myserver 0.0.1 and earlier
Timeline
- 2018-07-23: disclosed