Junglewise Threat Intelligence

CVE-2017-16199: susu-sum directory traversal

CVE-2017-16199 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

susu-sum is an npm package used for file serving in development environments. The package fails to properly validate file paths, allowing attackers to access sensitive files outside the intended directory—such as /etc/passwd on Linux systems. This could expose private configuration files, credentials, or source code from the server hosting the application.

Technical details

The vulnerability is a directory traversal (CWE-22) flaw in the susu-sum package, which resolves relative file paths without proper validation. An attacker can craft HTTP requests using path traversal sequences (e.g., /../../../../../../etc/passwd) to access files outside the intended directory root. The attack requires no authentication and is network-accessible, making it a trivial exploit. No patch is available; the advisory recommends the package be used only for local development or be replaced with an alternative.

Affected products

  • npm susu-sum 0.0.0 and later

Timeline

  • 2020-09-01: disclosed
  • 2017: other: CVE-2017-16199 assigned

References