{"id":"GHSA-f3vw-587g-r29g","summary":"Path Traversal in sapper","details":"Versions of `sapper` prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded `../`.  \n\nYou may test a `sapper` application running in prod mode with `curl -vvv http://localhost:3000/client/750af05c3a69ddc6073a/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd`.\n\n\n## Recommendation\n\nUpgrade to version 0.27.11 or later.","modified":"2020-08-31T19:01:20Z","published":"2020-09-03T15:50:38Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-08-31T19:01:20Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1494"}],"affected":[{"package":{"name":"sapper","ecosystem":"npm","purl":"pkg:npm/sapper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.27.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-f3vw-587g-r29g/GHSA-f3vw-587g-r29g.json"}}],"schema_version":"1.9.0"}