Junglewise Threat Intelligence

CVE-2019-5444: serve-here.js path traversal in URL handling

CVE-2019-5444 · Severity: low · CVSS 3 · Published 2021-09-22

Vendors: npm.

Executive brief

serve-here.js is a Node.js package used to serve static files over HTTP for local development or simple file sharing. The vulnerability allows attackers to bypass directory restrictions and access arbitrary files on the server by crafting URLs with path traversal sequences. This could expose sensitive configuration files, source code, private keys, or other confidential data stored on the server.

Technical details

The vulnerability is a classic path traversal (CWE-22) flaw in URL handling. The package fails to sanitize or validate user-supplied URLs before using them to access the filesystem, allowing relative path sequences such as `../` to traverse outside the configured serving directory. The attack requires only network access to the HTTP server and no authentication or user interaction. An attacker can craft URLs like `http://target:8000/../../etc/passwd` to read arbitrary files readable by the server process. The vulnerability was fixed in version 1.2.0, which properly sanitizes and validates file paths before serving them.

Affected products

  • Christopher Pytosh serve-here.js <1.2.0

Timeline

  • 2019-07-10: disclosed
  • 2021-09-22: advisory
  • 2021-09-22: patched: Fixed in version 1.2.0

References