{"id":"GHSA-x2jc-989c-47q4","summary":"Hexo `include_code` has a path traversal","details":"Hexo up to v7.1.1 was discovered to contain an arbitrary file read vulnerability.","aliases":["CVE-2023-39584"],"modified":"2025-09-05T13:29:14Z","published":"2023-09-08T15:30:18Z","database_specific":{"nvd_published_at":"2023-09-08T13:15:07Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-09-04T17:38:42Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39584"},{"type":"WEB","url":"https://github.com/hexojs/hexo/issues/5250"},{"type":"WEB","url":"https://github.com/hexojs/hexo/pull/5251"},{"type":"WEB","url":"https://github.com/hexojs/hexo/commit/b5b63caee27256d71a0cee8954c22375ec885d07"},{"type":"PACKAGE","url":"https://github.com/hexojs/hexo"},{"type":"WEB","url":"https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49"},{"type":"WEB","url":"https://github.com/hexojs/hexo/blob/cefee921153ba597316457f4fedf7b87b6516917/lib/plugins/tag/include_code.ts#L50"}],"affected":[{"package":{"name":"hexo","ecosystem":"npm","purl":"pkg:npm/hexo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-x2jc-989c-47q4/GHSA-x2jc-989c-47q4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}