Executive brief
serve-lite is a lightweight HTTP server library used for static file serving during web development. When serving a directory, it generates an HTML file listing without sanitizing file names, allowing an attacker to craft malicious file names containing JavaScript code that executes in a user's browser when they view the directory listing.
Technical details
The vulnerability is a reflected Cross-site Scripting (CWE-79) in the directory listing feature of serve-lite. The root cause is improper output encoding of file names in the dynamically generated HTML links; file names are inserted directly into href attributes and link text without sanitization. An attacker can exploit this by creating a file with an XSS payload in its name (e.g., `"><img src=x onerror=alert(1)>`), then tricking a user into browsing the directory via the serve-lite HTTP server. The attack requires user interaction (browsing to the directory) and network access to the server. A successful exploit allows arbitrary JavaScript execution in the victim's browser context. The vulnerability affects all versions up to and including 1.1.0; a fix was released in version 1.1.2.
Affected products
- npm serve-lite 0–1.1.0
Timeline
- 2022-11-21: disclosed: Vulnerability disclosed via GitHub gist
- 2023-05-02: patched: Fixed in version 1.1.2