md-fileserver@1.3.2 vulnerabilities

Locally view markdown files in a browser

Direct Vulnerabilities

Known vulnerabilities in the md-fileserver package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

md-fileserver is a library to locally view markdown files in a browser.

Affected versions of this package are vulnerable to Directory Traversal via the url which doesn't verify the file is from the root directory path.

How to fix Directory Traversal?

Upgrade md-fileserver to version 1.4.0 or higher.

>=1.3.2 <1.4.0