Loading HuntDB...

GHSA-rwv8-jvff-jq28

GitHub Security Advisory

Path Traversal in public

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions of `public` before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user.

## Recommendation

Update to version 0.1.3 or later.

Affected Packages

npm public
Affected versions: 0 (fixed in 0.1.3)

Related CVEs

Key Information

GHSA ID
GHSA-rwv8-jvff-jq28
Published
July 18, 2018 9:20 PM
Last Modified
January 31, 2023 1:37 AM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
public
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.