Junglewise Threat Intelligence

CVE-2017-16177: chatbyvista directory traversal

CVE-2017-16177 · Severity: info · Published 2020-09-01

Vendors: npm.

Executive brief

chatbyvista is a Node.js package used for serving web content. A directory traversal vulnerability allows attackers to request files outside the intended directory root, potentially exposing sensitive system files like /etc/passwd. No patch is available, and the vendor recommends using this package only for local development.

Technical details

The vulnerability exists in chatbyvista's file path resolution logic, which fails to properly sanitize relative path traversal sequences (../) in file requests. An unauthenticated attacker over the network can craft HTTP GET requests containing directory traversal payloads (e.g., GET /../../../../../../etc/passwd) to access files outside the intended web root. The CWE-22 class vulnerability allows disclosure of private files on the system. No patch is available; vendors recommend restricting use to local development environments only.

Affected products

  • chatbyvista chatbyvista all versions

Timeline

  • 2017: disclosed: CVE-2017-16177 published
  • 2020-09-01: advisory: GHSA-8w74-g84v-c5w8 published

References