Executive brief
mfrserver is a Node.js package used for serving files locally during development. A directory traversal vulnerability allows attackers to bypass intended directory restrictions and read arbitrary files from the system, potentially exposing sensitive configuration, private keys, or application data. This risk is particularly acute if the package is ever deployed beyond its intended local development use.
Technical details
mfrserver fails to properly validate and sanitize relative file paths in HTTP requests, allowing directory traversal attacks via sequences like `../../`. The vulnerability exists in all versions of the package (from 0.0.0 onward). An attacker can craft HTTP GET requests with relative path traversal sequences to access files outside the intended root directory—for example, `GET /../../../../../../../../../../etc/passwd` would read the system password file. Attack requires network access to the running mfrserver instance. No patch has been released; the advisory recommends restricting mfrserver to local development use only.
Affected products
- npm mfrserver all versions (0.0.0 onwards)
Timeline
- 2017: disclosed: CVE-2017-16213 assigned
- 2020-09-01: advisory: GHSA-p2r2-h92r-w2mg published