Junglewise Threat Intelligence

CVE-2017-16219: yttivy directory traversal

CVE-2017-16219 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

yttivy is a Node.js package used to serve web content during local development. A directory traversal vulnerability allows attackers to access files outside the intended directory root by crafting malicious URLs with path traversal sequences (e.g., `../../`), potentially exposing sensitive system files like configuration data or credentials to an unauthenticated attacker.

Technical details

The vulnerability is a classic directory traversal (CWE-22) caused by insufficient validation of relative file paths in yttivy's request handling. An unauthenticated attacker on the network can construct HTTP requests with path traversal sequences (e.g., `GET /../../../../../../etc/passwd`) to escape the intended directory root and read arbitrary files from the filesystem. The vulnerability is present in all versions of yttivy from 0.0.0 onward. No patch has been released; the package is recommended only for local development environments.

Affected products

  • npm yttivy all versions

Timeline

  • 2020-09-01: disclosed
  • other: CVE-2017-16219 assigned

References