Executive brief
wangguojing123 is a Node.js package that fails to properly validate file paths, allowing attackers to read arbitrary files on the server by using path traversal sequences (e.g., ../ in URLs). An attacker can exploit this to access sensitive files like /etc/passwd and other private data outside the intended application directory without authentication.
Technical details
The vulnerability is a path traversal (CWE-22) in wangguojing123 that occurs because the package resolves relative file paths without proper validation. An attacker can craft HTTP requests using directory traversal sequences (../) to escape the intended root directory and access arbitrary files on the system. The attack is network-accessible and requires no authentication. An exploit allows disclosure of sensitive files, including system configuration and private application data. No patch has been released; the vendor recommends restricting use to local development only.
Affected products
- wangguojing123 wangguojing123 all versions
Timeline
- 2020-09-01: disclosed
- 2017: other: CVE-2017-16150 assigned