Description
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.
Remediation
References
https://nodesecurity.io/advisories/9
Related Vulnerabilities
CVE-2020-11009 Vulnerability in maven package org.rundeck:rundeck
CVE-2022-31108 Vulnerability in maven package org.webjars.bower:mermaid
CVE-2020-7691 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2020-7768 Vulnerability in maven package org.webjars.npm:grpc
CVE-2019-12086 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind