CVE-2023-26126

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:m.static_project:m.static:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2023-05-10 05:15

Updated : 2023-11-07 04:09


NVD link : CVE-2023-26126

Mitre link : CVE-2023-26126

CVE.ORG link : CVE-2023-26126


JSON object : View

Products Affected

m.static_project

  • m.static
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')