Junglewise Threat Intelligence

@wturyn/swagger-injector path traversal in URL handling

Severity: info · CVSS 7.5 · Published 2020-09-03

Vendors: npm.

Executive brief

@wturyn/swagger-injector is a Node.js library used to inject Swagger API documentation into web applications. A path traversal vulnerability in the library's URL handling allows attackers to read arbitrary files from the server by using relative paths (e.g., "../../../etc/passwd") to escape the intended dist folder. This could expose sensitive configuration files, private keys, or other confidential data stored on the server.

Technical details

The vulnerability is a classic path traversal (CWE-22) flaw in which the package fails to properly validate or sanitize user-supplied URLs before using them to access the filesystem. The root cause lies in insufficient input validation when handling file paths, allowing an attacker to inject relative path sequences (e.g., "../") to escape the intended directory boundary. The attack vector is network-based and requires no authentication; an attacker can craft a malicious URL to request files outside the dist folder. An attacker who exploits this can read arbitrary files accessible to the web server process, including configuration files, source code, or cryptographic keys. No patch has been released as of the advisory publication date; the maintainers recommend switching to an alternative package.

Affected products

  • @wturyn swagger-injector all versions

Timeline

  • 2020-09-03: disclosed
  • other: GitHub advisory published; no fix available as of this date

References