Executive brief
directory-serve is a CLI tool that allows file transfer over a network. When run with the --delete option, a path traversal vulnerability allows unauthenticated attackers to delete arbitrary files on the server outside the intended directory. An attacker can exploit this to destroy critical files, disrupt operations, or damage system integrity.
Technical details
A path traversal vulnerability exists in the file-remove middleware of directory-serve through version 1.3.7. The vulnerable code directly concatenates user-supplied input (the 'file' parameter) with the base path without proper validation or normalization, allowing attackers to inject path traversal sequences (e.g., '../') to target files outside the served directory. The vulnerability is exposed when the application is run with the --delete option, which enables the file deletion functionality. An unauthenticated remote attacker can send a crafted HTTP request with traversal sequences to delete arbitrary files accessible by the server process. Patches or fixes in newer versions may include path validation and canonicalization to prevent directory escape.
Affected products
- cube-root directory-serve through 1.3.7
Timeline
- 2026-08-10: disclosed