Junglewise Threat Intelligence

CVE-2017-16224: npm st open redirect vulnerability

CVE-2017-16224 · Severity: low · CVSS 3 · Published 2018-08-06

Vendors: npm.

Executive brief

st is a Node.js module for serving static files over HTTP. An attacker can craft a specially formatted request to trick the module into redirecting users to an arbitrary external domain, potentially enabling phishing attacks or credential theft. This only affects servers hosting st from the root path (/) rather than a subdirectory, and requires user interaction (following the malicious link).

Technical details

st is vulnerable to an open redirect (CWE-601) allowing an attacker to craft HTTP requests with URL-encoded path traversal sequences (e.g., "//attacker.com/%2e%2e") that bypass path validation. When st serves from the root (/) rather than a subdirectory like (/static/), the vulnerable code returns a 301 redirect to the attacker-controlled domain. The attack requires user interaction (clicking a malicious link) and works only when URL-encoded parent directory references ("..") are present in the request path. The vulnerability is fixed in version 1.2.2 and later.

Affected products

  • npm st <= 1.2.1

Timeline

  • 2017-10-13: disclosed: Vulnerability demonstrated in proof-of-concept
  • 2018-08-06: advisory: GitHub Advisory published
  • 2018-08-06: patched: Version 1.2.2 or later fixes the vulnerability

Related threats