Junglewise Threat Intelligence

CVE-2017-16188: reecerver directory traversal

CVE-2017-16188 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

reecerver is a lightweight Node.js file-serving library used for local development. An attacker can use directory traversal sequences (e.g., `../../`) to access files outside the intended directory, potentially exposing sensitive files like private keys, configuration files, or system files on the developer's machine.

Technical details

The vulnerability exists in reecerver's path resolution logic, which fails to properly sanitize or validate relative file paths. An unauthenticated remote attacker can craft HTTP requests with directory traversal sequences (e.g., `GET /../../../../../../etc/passwd`) to bypass directory restrictions and access arbitrary files on the system. The attack requires network access to the reecerver instance and no authentication. An attacker can read any file accessible by the process running reecerver. No patch has been released; the vendor recommends using the package only for local development or switching to an alternative.

Affected products

  • reecerver reecerver through 0.1.2

Timeline

  • 2018-07-23: disclosed
  • other: CVE-2017-16188 assigned (published date discrepancy with OSV)

References