Junglewise Threat Intelligence

CVE-2017-16156: myprolyz directory traversal in file path resolution

CVE-2017-16156 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

myprolyz is a Node.js library used for file serving and path resolution. A directory traversal vulnerability allows attackers to access files outside the intended directory root by crafting requests with relative path sequences (e.g., `../../`), potentially exposing sensitive system files like `/etc/passwd`. This affects confidentiality but does not enable file modification or service disruption.

Technical details

The vulnerability is a classic directory traversal (CWE-22) in myprolyz's file path resolution logic. The library fails to properly normalize or validate relative file paths, allowing attackers to escape the intended directory root. Exploitation requires only network access and knowledge of the application's file structure; no authentication is needed. An attacker can send HTTP GET requests with traversal sequences (e.g., `GET /../../../../../../etc/passwd`) to read arbitrary files readable by the application process. No patch is available; the package maintainers recommend using it only for local development and selecting alternative libraries for production deployments.

Affected products

  • myprolyz myprolyz from 0.0.0

Timeline

  • 2020-09-01: disclosed: Advisory published on GitHub and OSV database
  • 2020-08-31: advisory: GitHub reviewed and categorized as HIGH severity

References