Junglewise Threat Intelligence

servey path traversal vulnerability

Severity: info · Published 2019-06-06

Vendors: npm.

Executive brief

servey is a Node.js library for handling file operations and serving content. Versions prior to 3.x contain a path traversal vulnerability that allows attackers to read arbitrary files from the server by crafting requests with relative paths, potentially exposing sensitive configuration files, source code, or other confidential data.

Technical details

The vulnerability is classified as CWE-22 (Path Traversal) and stems from insufficient input sanitization in path handling. Attackers can bypass directory restrictions by using relative path traversal sequences (e.g., ../../../etc/passwd) to access files outside the intended directory. The vulnerability is reachable over the network if servey is exposed via an HTTP interface. No authentication is required to exploit this issue. An attacker can read arbitrary files accessible to the servey process, including sensitive application and system files. The issue was fixed in version 3.1.0.

Affected products

  • npm servey prior to 3.1.0

Timeline

  • 2019-06-06: disclosed

References

Related threats