Loading HuntDB...

GHSA-m273-wwfv-h6jp

GitHub Security Advisory

Directory Traversal in fancy-server

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions 0.1.4 and earlier of fancy-server are vulnerable to a directory traversal attack.

Standard attack vectors such as `../` will allow an attacker to read files outside of the served directory.

## Recommendation

Upgrade to version 0.1.4 or greater.

Affected Packages

npm fancy-server
Affected versions: 0 (fixed in 0.1.4)

Related CVEs

Key Information

GHSA ID
GHSA-m273-wwfv-h6jp
Published
August 31, 2020 10:44 PM
Last Modified
August 31, 2020 6:07 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
fancy-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:21 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.