Executive brief
m.static is a lightweight static file server library for Node.js. The vulnerability allows attackers to read arbitrary files on the server by crafting requests with path traversal sequences (e.g., ../), bypassing the intended directory restrictions. This can expose sensitive configuration files, application code, and other confidential data stored on the server.
Technical details
The vulnerability is a CWE-22 path traversal flaw in the requestFile function due to improper input sanitization. The vulnerable code directly joins user-supplied URL paths with the configured working directory without validation: `const requestFile = join(options.cwd, req.url)`. An unauthenticated attacker can send HTTP requests with traversal sequences (../) to read files outside the intended static directory. No authentication or user interaction is required; the attack is triggered via a crafted HTTP request over the network. A patch has not been published; the package appears unmaintained (last published 4 years prior to disclosure).
Affected products
- ivoputzer m.static all versions up to and including 2.2.0
Timeline
- 2023-05-10: disclosed: CVE-2023-26126 published