7.3.0
12 years ago
5 months ago
Known vulnerabilities in the hexo package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
hexo is an A fast, simple & powerful blog framework, powered by Node.js. Affected versions of this package are vulnerable to Directory Traversal via the Hexo's file read functionality. An attacker can read arbitrary files by manipulating the file path input. Note: This issue is only exploitable if the attacker has the ability to control the file path input. This vulnerability was only verified successfully in the Windows environment. How to fix Directory Traversal? Upgrade | <7.2.0 |
hexo is an A fast, simple & powerful blog framework, powered by Node.js. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The POST How to fix Cross-site Scripting (XSS)? Upgrade | <6.0.0 |