GHSA-xqqr-p362-6rmc
GitHub Security Advisory
Directory Traversal in hostr
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Affected versions of `hostr` are vulnerable to directory traversal which allows attackers to read files outside the current directory by sending `../` in the url path for GET requests.
## Recommendation
Upgrade to version 2.3.6 or later.
Affected Packages
npm
hostr
Affected versions:
0
(fixed in 2.3.6)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.