Executive brief
The files-bucket-server package, a tool used to programmatically serve and manage local files via a web interface, is vulnerable to a security flaw that allows unauthorized file access. An attacker can use specially crafted web requests to bypass folder restrictions and view or delete sensitive files stored on the host server. This could lead to the exposure of private data or the accidental deletion of critical system files.
Technical details
A directory traversal vulnerability exists in all versions of files-bucket-server up to and including 1.2.6. The root cause is the improper sanitization of the ':filename' parameter in the RESTful API endpoints (specifically the DELETE and GET handlers). The application uses path.join() with unsanitized user input, allowing an attacker to use dot-dot-slash (../) sequences to escape the intended workspace directory. This enables unauthenticated remote attackers to read or delete arbitrary files on the filesystem that the process has permissions to access. As of the advisory date, no official patch has been released.
Affected products
- dsilva2401 files-bucket-server <= 1.2.6
Timeline
- 2024-12-24: other: Vulnerability research activity recorded
- 2025-07-23: disclosed: Vulnerability disclosed via GitHub Advisory and Snyk
- 2025-07-23: advisory: CVE-2025-8021 assigned