Executive brief
The npm package "public" is a web file serving utility that fails to properly restrict access to files outside its intended directory. An attacker can craft URLs containing symlinks to read arbitrary files from the server's filesystem, potentially exposing sensitive data, configuration files, or application code. No patch has been released, making this a persistent risk for any production deployment.
Technical details
This is a path traversal vulnerability (CWE-22) in the npm package "public" that affects all versions from 0.0.0 onward. The root cause is inadequate symlink handling in the URL routing logic—the application resolves symbolic links without proper validation, enabling attackers to escape the webroot directory. The attack vector is network-based with no authentication or special preconditions required; an unauthenticated attacker can send crafted HTTP requests containing symlink paths to access arbitrary files on the system. The vulnerability allows complete circumvention of directory restrictions, potentially leading to unauthorized file disclosure. No fix is currently available; the advisory recommends removing the module from production use or switching to an alternative solution.
Affected products
- npm public all versions
Timeline
- 2020-09-03: disclosed