Junglewise Threat Intelligence

CVE-2023-34238: Gatsby develop server local file inclusion vulnerability

CVE-2023-34238 · Severity: low · CVSS 3.1 · Published 2023-06-09

Executive brief

Gatsby is a popular framework for building web applications. The development server (gatsby develop) contains a path traversal flaw that allows an authenticated attacker with network access to read arbitrary files from the underlying system. By default, the server only listens on localhost and is safe; risk arises only when intentionally exposed to untrusted networks via configuration flags.

Technical details

A local file inclusion vulnerability exists in the __file-code-frame and __original-stack-frame endpoints of the Gatsby develop server. The vulnerability is rooted in insufficient input validation of the filePath and moduleId parameters, allowing attackers to perform path traversal (CWE-22). The attack requires network access to the development server (typically localhost) and authentication/trusted context on the local network. An attacker can exploit this by crafting malicious requests to read sensitive files such as /etc/passwd or configuration files containing credentials. Patches are available in Gatsby 4.25.7 and 5.9.1; versions prior to these (≤4.25.6 and ≤5.9.0 respectively) are affected.

Affected products

  • Gatsby Gatsby prior to 4.25.7 and 5.9.1

Timeline

  • 2023-06-09: disclosed: GHSA-c6f8-8r25-c4gc published
  • 2023-06-09: patched: Patches released in Gatsby 4.25.7 and 5.9.1

References