koa-body@2.5.0 vulnerabilities

A Koa body parser middleware. Supports multipart, urlencoded and JSON request bodies.

  • latest version

    6.0.1

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    2 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the koa-body package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    koa-body is A koa body parser middleware. Support multipart, urlencoded and json request bodies.

    Affected versions of the package are vulnerable to Directory Traversal. An attacker may POST or PUT a request to the /upload-files endpoint and make the request handler think a file has been uploaded to /any/file/path. By using paths of sensitive files an attacker would be able to read private keys, configuration files and passwords.

    How to fix Directory Traversal?

    There is no fix version for koa-body.

    <3.0.0