Executive brief
uekw1511server is a Node.js package providing local file serving functionality. A directory traversal vulnerability allows attackers to read arbitrary files outside the intended directory root by crafting requests with path traversal sequences, potentially exposing sensitive system files like credentials and configuration data. No patch is available; the vendor recommends using the package only for local development.
Technical details
A directory traversal (CWE-22) vulnerability exists in uekw1511server due to insufficient validation of relative file paths in HTTP requests. An unauthenticated attacker on the network can send specially crafted GET requests containing traversal sequences (e.g., /../../../etc/passwd) to access files outside the intended directory root. The vulnerability is network-reachable and requires no authentication or user interaction. An attacker can read arbitrary files accessible to the process, resulting in confidentiality compromise. No patch has been released; the vendor recommends restricting the package to local development use only.
Affected products
- <UNKNOWN> uekw1511server all versions from 0.0.0
Timeline
- 2020-09-01: disclosed