Executive brief
sgqserve is a Node.js package used as a simple local file server for development purposes. A directory traversal vulnerability allows an attacker to read arbitrary files on the system by requesting paths with relative directory traversal sequences (e.g., ../../etc/passwd), potentially exposing sensitive configuration files, source code, or other private data.
Technical details
sgqserve contains a directory traversal vulnerability (CWE-22) in its path resolution logic that fails to properly sanitize relative file paths. An unauthenticated attacker with network access to the server can exploit this by sending HTTP GET requests with traversal sequences (../) to access files outside the intended document root. No authentication or user interaction is required; the vulnerability is exploitable via network requests alone. This can lead to disclosure of arbitrary files readable by the process owner. No patch is available; the maintainers recommend using this package only for local development and switching to an alternative for production use.
Affected products
- npm sgqserve all versions
Timeline
- 2017: disclosed: CVE-2017-16215 assigned
- 2020-09-01: advisory: GHSA-m8pw-hgvj-cwcm published