Executive brief
crud-file-server is a lightweight Node.js file server that displays directory listings in the browser. Versions before 0.8.0 fail to sanitize filenames when rendering directory indexes, allowing an attacker to create files with malicious HTML or JavaScript in their names. When other users browse the directory, the injected script executes in their browser, potentially stealing session tokens or redirecting them to phishing sites.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the directory index rendering logic. When serving a directory listing, crud-file-server versions <= 0.7.0 fail to HTML-encode filenames before inserting them into the response page, violating CWE-79. An unauthenticated attacker with write access to the file server can create files with JavaScript payloads in their names (e.g., "<img src=x onerror='alert(1)'>.txt"). Since the vulnerability affects the directory index served to any client accessing the directory, the attack requires no authentication or user interaction beyond visiting the directory. The fix, released in version 0.8.0, adds proper HTML escaping of filenames in the rendered output.
Affected products
- npm crud-file-server < 0.8.0
Timeline
- 2018-06-07: disclosed: Vulnerability published to NVD
- 2018-07-18: patched: Version 0.8.0 released with sanitization fix
- 2018-07-18: advisory: GHSA-h24f-9mm4-w336 published