Junglewise Threat Intelligence

CVE-2023-26126: m.static directory traversal vulnerability

CVE-2023-26126 · Severity: low · CVSS 3.1 · Published 2023-05-10

Vendors: npm.

Executive brief

m.static is a lightweight static file server library for Node.js. The vulnerability allows attackers to read arbitrary files on the server by crafting requests with path traversal sequences (e.g., ../), bypassing the intended directory restrictions. This can expose sensitive configuration files, application code, and other confidential data stored on the server.

Technical details

The vulnerability is a CWE-22 path traversal flaw in the requestFile function due to improper input sanitization. The vulnerable code directly joins user-supplied URL paths with the configured working directory without validation: `const requestFile = join(options.cwd, req.url)`. An unauthenticated attacker can send HTTP requests with traversal sequences (../) to read files outside the intended static directory. No authentication or user interaction is required; the attack is triggered via a crafted HTTP request over the network. A patch has not been published; the package appears unmaintained (last published 4 years prior to disclosure).

Affected products

  • ivoputzer m.static all versions up to and including 2.2.0

Timeline

  • 2023-05-10: disclosed: CVE-2023-26126 published

References