GHSA-4wch-fwmx-cf47
GitHub Security Advisory
Directory Traversal in augustine
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Affected versions of `augustine` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system.
## Proof of Concept
```http
GET //etc/passwd HTTP/1.1
host:foo
```
## Recommendation
No direct patch is available at this time.
Currently, the best mitigation for this flaw is to use a different, functionally equivalent static file server package.
Affected Packages
npm
augustine
Affected versions:
0
(last affected: 0.2.3)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.