Executive brief
sly07 is an npm package used to serve local files and directories. The package fails to properly sanitize relative file paths, allowing an attacker to access files outside the intended directory root using path traversal sequences like `../../`. An attacker can read sensitive files on the system where sly07 is running, such as configuration files or private keys, without authentication.
Technical details
The vulnerability is a classic directory traversal (CWE-22) affecting sly07 versions up to 0.1.2. The root cause is improper normalization of file paths before resolving them on the filesystem; the application does not properly block or sanitize traversal sequences (e.g., `../`). An attacker can send HTTP GET requests with path traversal payloads (e.g., `GET /../../../../../../etc/passwd`) to access arbitrary files readable by the process. The attack requires only network access to the server; no authentication or user interaction is needed. An attacker can disclose private files on the vulnerable system. No patch has been released; the vendor recommends restricting sly07 to local development only.
Affected products
- npm sly07 0.1.2 and earlier
Timeline
- 2018-07-23: disclosed