Executive brief
dmmcquay.lab6 is a Node.js package used for local development that serves files from a directory. A directory traversal vulnerability allows attackers to bypass access restrictions and read arbitrary files on the system—such as configuration files, credentials, or other sensitive data—by using specially crafted URLs with path traversal sequences (e.g., "../../etc/passwd").
Technical details
The vulnerability is a path traversal (CWE-22) in dmmcquay.lab6 caused by insufficient validation of relative file paths before serving them. An unauthenticated attacker can craft HTTP requests with sequences like "/../" to traverse outside the intended document root and access arbitrary files readable by the application process. No authentication or user interaction is required; exploitation is straightforward via simple HTTP GET requests. The package is affected across all versions from 0.0.0 onwards. No patch has been released; the advisory recommends the package be used only for local development and not in production environments.
Affected products
- dmmcquay lab6 all versions from 0.0.0
Timeline
- 2020-09-01: disclosed