Junglewise Threat Intelligence

CVE-2022-25847: serve-lite Cross-site Scripting in directory listing

CVE-2022-25847 · Severity: low · CVSS 3.1 · Published 2023-01-26

Vendors: npm.

Executive brief

serve-lite is a lightweight HTTP server library used for static file serving during web development. When serving a directory, it generates an HTML file listing without sanitizing file names, allowing an attacker to craft malicious file names containing JavaScript code that executes in a user's browser when they view the directory listing.

Technical details

The vulnerability is a reflected Cross-site Scripting (CWE-79) in the directory listing feature of serve-lite. The root cause is improper output encoding of file names in the dynamically generated HTML links; file names are inserted directly into href attributes and link text without sanitization. An attacker can exploit this by creating a file with an XSS payload in its name (e.g., `"><img src=x onerror=alert(1)>`), then tricking a user into browsing the directory via the serve-lite HTTP server. The attack requires user interaction (browsing to the directory) and network access to the server. A successful exploit allows arbitrary JavaScript execution in the victim's browser context. The vulnerability affects all versions up to and including 1.1.0; a fix was released in version 1.1.2.

Affected products

  • npm serve-lite 0–1.1.0

Timeline

  • 2022-11-21: disclosed: Vulnerability disclosed via GitHub gist
  • 2023-05-02: patched: Fixed in version 1.1.2

References

Related threats