Executive brief
The "public" npm package is a lightweight HTTP server for serving static files. Versions before 0.1.3 fail to properly validate file paths, allowing an attacker to read arbitrary files accessible to the server process. This could expose sensitive configuration files, source code, or other confidential data stored on the same system.
Technical details
The vulnerability is a classic path traversal (CWE-22) caused by insufficient sanitization of user-supplied file paths. The vulnerable component is the file path handling logic in the HTTP request handler, which does not resolve and validate paths against a configured root directory. An unauthenticated attacker can send requests with traversal sequences (e.g., "../../../etc/passwd") to read arbitrary files. The attack requires only network access to the HTTP server and no user interaction. Fix is available in version 0.1.3 and later, which adds proper path resolution and validation.
Affected products
- npm public before 0.1.3
Timeline
- 2018-06-07: disclosed
- 2018-07-18: advisory
- 2018-07-18: patched: Fixed in version 0.1.3