Executive brief
ewgaddis.lab6 is a Node.js library that fails to properly validate file paths, allowing attackers to read arbitrary files outside the intended directory. An unauthenticated attacker can craft a simple HTTP request with path traversal sequences (e.g., `/../../../etc/passwd`) to access sensitive files on the system, potentially exposing configuration data, private keys, or other confidential information.
Technical details
ewgaddis.lab6 contains a path traversal vulnerability (CWE-22) where relative file paths are resolved without proper normalization or restriction to a base directory. The vulnerability is accessible via network requests containing relative path sequences (e.g., `GET /../../../../../../etc/passwd`). No authentication or user interaction is required; the attack surface is exposed to any network-accessible instance. An attacker can read arbitrary files accessible to the process, leading to information disclosure of sensitive data. No patch has been released; the package maintainers recommend using it only for local development and substituting an alternative package for production use.
Affected products
- ewgaddis lab6 <= 0.1.1
Timeline
- 2018-07-23: disclosed: Published to GitHub Advisory Database