Executive brief
fbr-client is a Node.js package for file serving. The package fails to properly validate relative file paths, allowing an attacker to access arbitrary files outside the intended directory—such as sensitive system files or private data on the server. With no patch available, the package is unsafe for production use.
Technical details
The vulnerability is a classic directory traversal (CWE-22) caused by improper resolution of relative file paths in fbr-client versions up to 1.0.3. An attacker can craft HTTP requests using path traversal sequences (e.g., /../../../etc/passwd) to access files outside the intended root directory. No authentication or user interaction is required; the vulnerability is reachable over the network via simple HTTP GET requests. An attacker can read arbitrary files accessible to the process, leading to disclosure of sensitive data. No patch has been released; the vendor recommends using the package only for local development and switching to an alternative package for production deployments.
Affected products
- fbr-client fbr-client up to 1.0.3
Timeline
- 2018-07-23: disclosed
- other: CVE-2017-16217 assigned