Executive brief
susu-sum is an npm package used for file serving in development environments. The package fails to properly validate file paths, allowing attackers to access sensitive files outside the intended directory—such as /etc/passwd on Linux systems. This could expose private configuration files, credentials, or source code from the server hosting the application.
Technical details
The vulnerability is a directory traversal (CWE-22) flaw in the susu-sum package, which resolves relative file paths without proper validation. An attacker can craft HTTP requests using path traversal sequences (e.g., /../../../../../../etc/passwd) to access files outside the intended directory root. The attack requires no authentication and is network-accessible, making it a trivial exploit. No patch is available; the advisory recommends the package be used only for local development or be replaced with an alternative.
Affected products
- npm susu-sum 0.0.0 and later
Timeline
- 2020-09-01: disclosed
- 2017: other: CVE-2017-16199 assigned