Junglewise Threat Intelligence

CVE-2021-25864: node-red-contrib-huemagic path traversal in res.sendFile

CVE-2021-25864 · Severity: low · CVSS 3.1 · Published 2021-04-13

Vendors: npm.

Executive brief

node-red-contrib-huemagic is a Node-RED plugin that integrates Philips Hue smart lighting systems into Node-RED flows. A path traversal vulnerability in the file serving endpoint allows unauthenticated attackers to download arbitrary files from the server (such as /etc/passwd) by manipulating the file path parameter. This could expose sensitive configuration files, private keys, or other confidential data stored on the server.

Technical details

The vulnerability is a classic path traversal (CWE-22) in the res.sendFile API call within hue-magic.js. The vulnerable code constructs a file path using user-supplied parameters without proper validation, allowing attackers to use sequences like ..%2F (URL-encoded directory traversal) to escape the intended 'animations/previews' directory. The endpoint lacks RED.auth.needsPermission authentication checks, making it accessible to any network-connected attacker without credentials. An attacker can craft requests such as /hue/assets/..%2F..%2F..%2Fetc%2Fpasswd to retrieve arbitrary files with the privileges of the Node-RED process. The vulnerability affects version 3.0.0 and earlier; patches implementing the dotfiles: deny option in res.sendFile are available.

Affected products

  • node-red-contrib-huemagic node-red-contrib-huemagic up to 3.0.0

Timeline

  • 2021-01-17: disclosed: Vulnerability reported in GitHub issue #217
  • 2021-01-26: advisory: Published to NVD
  • 2021-04-13: advisory: GHSA advisory published

References