koa-body@2.6.0 vulnerabilities

A Koa body parser middleware. Supports multipart, urlencoded and JSON request bodies.

Direct Vulnerabilities

Known vulnerabilities in the koa-body package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

koa-body is A koa body parser middleware. Support multipart, urlencoded and json request bodies.

Affected versions of the package are vulnerable to Directory Traversal. An attacker may POST or PUT a request to the /upload-files endpoint and make the request handler think a file has been uploaded to /any/file/path. By using paths of sensitive files an attacker would be able to read private keys, configuration files and passwords.

How to fix Directory Traversal?

There is no fix version for koa-body.

<3.0.0