Executive brief
node-red-contrib-huemagic is a Node-RED plugin that integrates Philips Hue smart lighting systems into Node-RED flows. A path traversal vulnerability in the file serving endpoint allows unauthenticated attackers to download arbitrary files from the server (such as /etc/passwd) by manipulating the file path parameter. This could expose sensitive configuration files, private keys, or other confidential data stored on the server.
Technical details
The vulnerability is a classic path traversal (CWE-22) in the res.sendFile API call within hue-magic.js. The vulnerable code constructs a file path using user-supplied parameters without proper validation, allowing attackers to use sequences like ..%2F (URL-encoded directory traversal) to escape the intended 'animations/previews' directory. The endpoint lacks RED.auth.needsPermission authentication checks, making it accessible to any network-connected attacker without credentials. An attacker can craft requests such as /hue/assets/..%2F..%2F..%2Fetc%2Fpasswd to retrieve arbitrary files with the privileges of the Node-RED process. The vulnerability affects version 3.0.0 and earlier; patches implementing the dotfiles: deny option in res.sendFile are available.
Affected products
- node-red-contrib-huemagic node-red-contrib-huemagic up to 3.0.0
Timeline
- 2021-01-17: disclosed: Vulnerability reported in GitHub issue #217
- 2021-01-26: advisory: Published to NVD
- 2021-04-13: advisory: GHSA advisory published