PT-2022-17565 · Unknown · Static-Dev-Server

Liran Tal

·

Published

2022-11-29

·

Updated

2025-04-24

·

CVE-2022-25848

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions static-dev-server versions all
Description A path traversal issue affects the package. This occurs because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-25848
GHSA-7FXM-C848-89Q8

Affected Products

Static-Dev-Server