Loading HuntDB...

GHSA-g4xp-36c3-f7mr

GitHub Security Advisory

Hidden Directories Always Served in inert

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Versions 1.1.1 and earlier of `inert` are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false.

The inert directory handler always allows files in hidden directories to be served, even when `showHidden` is false.

## Recommendation

Update to version >= 1.1.1.

Affected Packages

npm inert
Affected versions: 0 (fixed in 1.1.1)

Related CVEs

Key Information

GHSA ID
GHSA-g4xp-36c3-f7mr
Published
August 31, 2020 10:47 PM
Last Modified
August 31, 2020 6:07 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
inert
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.