Executive brief
takeapeek is a static file server used to host and serve files over a network. A security flaw allows unauthorized users to bypass folder restrictions and view files or directories on the host system that should not be accessible. This could lead to the exposure of sensitive configuration files or internal data.
Technical details
A path traversal vulnerability (CWE-22) exists in all versions of the takeapeek npm module up to and including 0.2.2. The root cause is the failure to properly neutralize special elements within the pathname provided by the user, allowing an attacker to use 'dot-dot-slash' (../) sequences to escape the restricted directory. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation allows an attacker to list directories and read arbitrary files on the server. As of the advisory date, no patch is available, and users are advised to migrate to an alternative static file server.
Affected products
- takeapeek project takeapeek <= 0.2.2
Timeline
- 2018-09-01: other: Vulnerability reported via HackerOne
- 2018-11-06: disclosed: Public disclosure of the vulnerability
- 2018-11-06: advisory: NVD and GitHub advisories published