Executive brief
Gatsby is a popular framework for building web applications. The development server (gatsby develop) contains a path traversal flaw that allows an authenticated attacker with network access to read arbitrary files from the underlying system. By default, the server only listens on localhost and is safe; risk arises only when intentionally exposed to untrusted networks via configuration flags.
Technical details
A local file inclusion vulnerability exists in the __file-code-frame and __original-stack-frame endpoints of the Gatsby develop server. The vulnerability is rooted in insufficient input validation of the filePath and moduleId parameters, allowing attackers to perform path traversal (CWE-22). The attack requires network access to the development server (typically localhost) and authentication/trusted context on the local network. An attacker can exploit this by crafting malicious requests to read sensitive files such as /etc/passwd or configuration files containing credentials. Patches are available in Gatsby 4.25.7 and 5.9.1; versions prior to these (≤4.25.6 and ≤5.9.0 respectively) are affected.
Affected products
- Gatsby Gatsby prior to 4.25.7 and 5.9.1
Timeline
- 2023-06-09: disclosed: GHSA-c6f8-8r25-c4gc published
- 2023-06-09: patched: Patches released in Gatsby 4.25.7 and 5.9.1