Executive brief
whispercast is a Node.js package used to serve static files and content. The vulnerability allows attackers to read arbitrary files on the system by traversing outside the intended directory, potentially exposing sensitive data such as configuration files, private keys, or system files. No patch is available.
Technical details
The vulnerability is a directory traversal (CWE-22) issue where whispercast fails to properly validate and sanitize relative file paths. An attacker can craft HTTP requests using path traversal sequences (e.g., "../../etc/passwd") to access files outside the intended root directory. The vulnerability is network-reachable with no authentication or user interaction required. An attacker can achieve arbitrary file read, disclosing sensitive files and potentially extracting credentials or configuration data. No patch is available; the developers recommend using the package only for local development.
Affected products
- npm whispercast 0.1.0 and earlier
Timeline
- 2018-07-23: disclosed: Advisory published on GitHub
- 2017: other: Vulnerability originally identified (CVE-2017-16174)