lite-dev-server vulnerable to Directory Traversal
High severity
GitHub Reviewed
Published
Dec 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Dec 21, 2022
Published to the GitHub Advisory Database
Dec 21, 2022
Reviewed
Dec 21, 2022
Last updated
Jan 27, 2023
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the
req.url
user input that is passed to the server code.References