7.4.5
13 years ago
25 days ago
Known vulnerabilities in the webpack-dev-middleware package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Path Traversal due to insufficient validation of the supplied URL address before returning the local file. This issue allows accessing any file on the developer's machine. The middleware can operate with either the physical filesystem or a virtualized in-memory Notes:
How to fix Path Traversal? Upgrade | <5.3.4>=6.0.0 <6.1.2>=7.0.0 <7.1.0 |