Loading HuntDB...

GHSA-7c9w-qmrq-ff8r

GitHub Security Advisory

Path Traversal in http-live-simulator

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions of `http-live-simulator` prior to 1.0.7 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. For example: `curl --path-as-is http://localhost:8080//../../../../etc/passwd`.

## Recommendation

Upgrade to version 1.0.7

Affected Packages

npm http-live-simulator
Affected versions: 0 (fixed in 1.0.7)

Related CVEs

Key Information

GHSA ID
GHSA-7c9w-qmrq-ff8r
Published
February 7, 2019 6:14 PM
Last Modified
August 31, 2020 6:35 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
http-live-simulator
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 30, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.