Loading HuntDB...

GHSA-3r8f-gphx-9m2c

GitHub Security Advisory

Path Traversal in mcstatic

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

All versions of `mcstatic` are vulnerable to path traversal.

## Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.

Affected Packages

npm mcstatic
Affected versions: 0 (last affected: 0.0.20)

Related CVEs

Key Information

GHSA ID
GHSA-3r8f-gphx-9m2c
Published
July 27, 2018 5:04 PM
Last Modified
January 31, 2023 1:38 AM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
mcstatic
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.