Junglewise Threat Intelligence

CVE-2021-23430: startserver directory traversal

CVE-2021-23430 · Severity: low · CVSS 3.1 · Published 2021-09-02

Vendors: npm.

Executive brief

startserver is a lightweight Node.js HTTP server library. A directory traversal vulnerability allows attackers to read arbitrary files on the server by crafting malicious HTTP requests with path traversal sequences. This could expose sensitive configuration files, source code, or other confidential data stored on the server.

Technical details

The vulnerability is a CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) directory traversal flaw affecting all versions of startserver up to and including 1.4.1. The root cause is missing input sanitization in the HTTP request handling logic (in lib/index.js around line 71), which fails to filter or normalize path traversal sequences such as "../" before serving files. The attack requires only network access (no authentication or user interaction needed) and can be exploited to read arbitrary files outside the intended server directory. No patch information is currently available in the advisory; users should upgrade to a patched version or implement external path validation if available.

Affected products

  • xudafeng startserver up to 1.4.1

Timeline

  • 2021-08-24: disclosed
  • 2021-09-02: advisory

References