koa-body@2.5.0 vulnerabilities

A Koa body parser middleware. Supports multipart, urlencoded and JSON request bodies.

Direct Vulnerabilities

Known vulnerabilities in the koa-body package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Directory Traversal

koa-body is A koa body parser middleware. Support multipart, urlencoded and json request bodies.

Affected versions of the package are vulnerable to Directory Traversal. An attacker may POST or PUT a request to the /upload-files endpoint and make the request handler think a file has been uploaded to /any/file/path. By using paths of sensitive files an attacker would be able to read private keys, configuration files and passwords.

How to fix Directory Traversal?

There is no fix version for koa-body.