Executive brief
Harp is a Node.js static web server and development tool. A vulnerability allows attackers to read arbitrary files outside the intended project directory by exploiting symlinks in the project folder. This could expose sensitive configuration files, credentials, or other confidential data on the server.
Technical details
Harp contains a path traversal vulnerability (CWE-22) in its file serving mechanism. If a symlink exists in the project's base directory that points to a file outside the project directory, the server will follow the symlink and serve the target file without restriction. An unauthenticated network attacker can exploit this by accessing the symlink path, allowing arbitrary file read access. No patch is currently available; all versions through 0.40.2 are vulnerable.
Affected products
- Harp harp all versions before 0.40.3
Timeline
- 2019-06-13: disclosed