Executive brief
marscode is a web-based file editor that allows users to read, write, and manage files on a server. The application fails to properly validate file paths, allowing an attacker to access files outside the intended directory—such as configuration files, source code, or system credentials—by using path traversal sequences like "../". This could expose sensitive information that could be used in further attacks.
Technical details
The vulnerability is a classic directory traversal (CWE-22) in the fs.readFile functionality of marscode's index.js file. The application does not sanitize or validate the file path parameter before reading files from the filesystem. An unauthenticated attacker can send HTTP requests with path traversal sequences (e.g., "/../../../sensitive-file") to access arbitrary files on the server. The vulnerability is exploitable remotely over the network without authentication or user interaction. While the current impact is limited to information disclosure (confidentiality), there is no patch available as of the advisory date; users must implement workarounds or migrate to alternative solutions.
Affected products
- marscode marscode up to and including 1.0.1-0
Timeline
- 2020-06-20: disclosed
- 2021-05-07: advisory