ZeroHour

Vulnerabilities

1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26111
All versions of the package @nubosoftware/node-static;

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

NVD description · AI analysis pending
7.51% PoC ×3
  • \@nubosoftware\/node-static project \@nubosoftware\/node-static
  • \@nubosoftware\/node-static project node-static