Executive brief
yttivy is a Node.js package used to serve web content during local development. A directory traversal vulnerability allows attackers to access files outside the intended directory root by crafting malicious URLs with path traversal sequences (e.g., `../../`), potentially exposing sensitive system files like configuration data or credentials to an unauthenticated attacker.
Technical details
The vulnerability is a classic directory traversal (CWE-22) caused by insufficient validation of relative file paths in yttivy's request handling. An unauthenticated attacker on the network can construct HTTP requests with path traversal sequences (e.g., `GET /../../../../../../etc/passwd`) to escape the intended directory root and read arbitrary files from the filesystem. The vulnerability is present in all versions of yttivy from 0.0.0 onward. No patch has been released; the package is recommended only for local development environments.
Affected products
- npm yttivy all versions
Timeline
- 2020-09-01: disclosed
- other: CVE-2017-16219 assigned