Loading HuntDB...

GHSA-q2qh-cgc2-qhr3

GitHub Security Advisory

Directory Traversal in serve

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Affected versions of `serve` do not properly handle `%2e` (.) and `%2f` (/) characters, and allow the, characters to be used in paths. This can be used to traverse the directory tree and list content of any directory the user running the process has access to.

Mitigating factors:
This vulnerability only allows listing of directory contents and does not allow reading of arbitrary files.

## Recommendation

Update to version 6.4.9 later.

Affected Packages

npm serve
Affected versions: 0 (fixed in 6.4.9)

Related CVEs

Key Information

GHSA ID
GHSA-q2qh-cgc2-qhr3
Published
July 27, 2018 5:07 PM
Last Modified
April 21, 2023 7:00 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
serve
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.