Junglewise Threat Intelligence

CVE-2017-16163: dylmomo directory traversal

CVE-2017-16163 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

dylmomo is a Node.js package for file serving or web development. A directory traversal vulnerability allows attackers to access files outside the intended root directory by crafting requests with path sequences like "../../etc/passwd", potentially exposing sensitive system files and private data.

Technical details

This is a path traversal vulnerability (CWE-22) in the dylmomo npm package affecting all versions from 0.0.0. The vulnerability exists because the package fails to properly sanitize relative file paths, allowing an attacker to navigate outside the intended directory root using sequences like "../". The attack is network-accessible, requires no authentication or user interaction, and allows an unauthenticated remote attacker to read arbitrary files on the system with the permissions of the process running dylmomo. The vulnerability enables information disclosure of sensitive files such as /etc/passwd and application configuration files. No patch is available; the maintainers recommend restricting use to local development only.

Affected products

  • npm dylmomo all versions from 0.0.0

Timeline

  • 2020-09-01: disclosed: Advisory published to GitHub Security Advisory database

References