{"id":"GHSA-m33v-338h-4v9f","summary":"Path traversal in Node-Red","details":"### Impact\n\nThis vulnerability allows arbitrary path traversal via the Projects API.\n\nIf the Projects feature is enabled, a user with `projects.read` permission is able to access any file via the Projects API.\n\n### Patches\n\nThe issue has been patched in Node-RED 1.2.8\n\n### Workarounds\n\nThe vulnerability applies only to the Projects feature which is not enabled by default in Node-RED.\n\nThe primary workaround is not give untrusted users read access to the Node-RED editor.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [team@nodered.org](mailto:team@nodered.org)\n\n### Acknowledgements\n\nThanks to the Tencent Woodpecker Security Team for disclosing this vulnerability.","aliases":["CVE-2021-21298"],"modified":"2026-07-08T06:28:45.954945204Z","published":"2021-02-26T16:31:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-02-26T16:23:34Z","nvd_published_at":"2021-02-26T17:15:00Z","cwe_ids":["CWE-22"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/node-red/node-red/security/advisories/GHSA-m33v-338h-4v9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21298"},{"type":"WEB","url":"https://github.com/node-red/node-red/commit/74db3e17d075f23d9c95d7871586cf461524c456"},{"type":"WEB","url":"https://github.com/node-red/node-red/releases/tag/1.2.8"},{"type":"WEB","url":"https://www.npmjs.com/package/@node-red/runtime"}],"affected":[{"package":{"name":"@node-red/runtime","ecosystem":"npm","purl":"pkg:npm/%40node-red/runtime"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-m33v-338h-4v9f/GHSA-m33v-338h-4v9f.json"}}],"schema_version":"1.9.0"}