Geddy prior to version 13.0.8 contains a directory traversal vulnerability in lib/app/index.js that allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
id: CVE-2015-5688
info:
name: Geddy <13.0.8 - Local File Inclusion
author: pikpikcu
severity:
...