Junglewise Threat Intelligence

CVE-2018-3731: npm public path traversal

CVE-2018-3731 · Severity: low · CVSS 3.1 · Published 2018-07-18

Technologies: public (npm). Vendors: npm.

Executive brief

The "public" npm package is a lightweight HTTP server for serving static files. Versions before 0.1.3 fail to properly validate file paths, allowing an attacker to read arbitrary files accessible to the server process. This could expose sensitive configuration files, source code, or other confidential data stored on the same system.

Technical details

The vulnerability is a classic path traversal (CWE-22) caused by insufficient sanitization of user-supplied file paths. The vulnerable component is the file path handling logic in the HTTP request handler, which does not resolve and validate paths against a configured root directory. An unauthenticated attacker can send requests with traversal sequences (e.g., "../../../etc/passwd") to read arbitrary files. The attack requires only network access to the HTTP server and no user interaction. Fix is available in version 0.1.3 and later, which adds proper path resolution and validation.

Affected products

  • npm public before 0.1.3

Timeline

  • 2018-06-07: disclosed
  • 2018-07-18: advisory
  • 2018-07-18: patched: Fixed in version 0.1.3

References

Related threats