Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
m.static 路径遍历漏洞
Vulnerability Description
npm m.static是美国npm公司的一个用 es6+ 编写的用于 node.js 的轻量级静态文件服务器。 m.static存在安全漏洞,该漏洞源于对通过requestFile函数请求的路径进行了不正确的输入清理。
CVSS Information
N/A
Vulnerability Type
N/A