http-server-node@1.0.1 vulnerabilities

simple, zero-configuration command-line http server

Direct Vulnerabilities

Known vulnerabilities in the http-server-node package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Directory Traversal

http-server-node is a simple, zero-configuration command-line http server

Affected versions of this package are vulnerable to Directory Traversal via use of --path-as-is.

##PoC

curl -s --path-as-is http://127.0.0.1:3000/../sensitive-file.txt

How to fix Directory Traversal?

There is no fixed version for http-server-node.

*