GHSA-cqv6-7fwc-8m3c
GitHub Security Advisory
Directory Traversal in xtalk
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Affected versions of `xtalk` are vulnerable to directory traversal, allowing access to the filesystem by placing "../" in the URL.
**Example request:**
```http
GET /../../../../../../../../../../etc/passwd HTTP/1.1
host:localhost
```
## Recommendation
No patch is currently available for this vulnerability, and the package has not been updated since 2014.
The best mitigation is currently to avoid using this package, and using a different, functionally equivalent package.
Affected Packages
npm
xtalk
Affected versions:
0.0.2
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.