Executive brief
The ltt package is a Node.js library used for local file serving in development environments. Due to improper path validation, an attacker can use specially crafted URLs with "../" sequences to access files outside the intended directory, potentially exposing sensitive files like configuration data, private keys, or system files. Since no patch exists, the package should only be used for local development and never in production.
Technical details
The vulnerability is a classic path traversal (CWE-22) caused by ltt's failure to neutralize directory traversal sequences (../) in file path resolution. The vulnerable component is the file serving mechanism that processes user-supplied paths without proper canonicalization or validation. An unauthenticated remote attacker can send HTTP requests with encoded or unencoded traversal sequences (e.g., GET /../../../../../../etc/passwd) to read arbitrary files accessible by the process. The attack requires network access but no authentication, user interaction, or special privileges. The impact is limited to confidentiality (file disclosure); there is no modification or availability impact. No patch is available from the maintainers; mitigation requires retiring the package or restricting its use to isolated local development environments only.
Affected products
- npm ltt <=1.1.0
Timeline
- 2018-07-23: disclosed