Junglewise Threat Intelligence

CVE-2017-16174: whispercast directory traversal

CVE-2017-16174 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

whispercast is a Node.js package used to serve static files and content. The vulnerability allows attackers to read arbitrary files on the system by traversing outside the intended directory, potentially exposing sensitive data such as configuration files, private keys, or system files. No patch is available.

Technical details

The vulnerability is a directory traversal (CWE-22) issue where whispercast fails to properly validate and sanitize relative file paths. An attacker can craft HTTP requests using path traversal sequences (e.g., "../../etc/passwd") to access files outside the intended root directory. The vulnerability is network-reachable with no authentication or user interaction required. An attacker can achieve arbitrary file read, disclosing sensitive files and potentially extracting credentials or configuration data. No patch is available; the developers recommend using the package only for local development.

Affected products

  • npm whispercast 0.1.0 and earlier

Timeline

  • 2018-07-23: disclosed: Advisory published on GitHub
  • 2017: other: Vulnerability originally identified (CVE-2017-16174)

References