PT-2026-66884 · Rubygems · Guard-Livereload
CVE-2016-1000305
·
Published
2026-07-31
·
Updated
2026-07-31
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
The vulnerability allows remote attackers to read arbitrary files
on the server by exploiting improper path validation in the
livereload server functionality.
This vulnerability is related to the handling of file paths in the
livereload server component, which could allow an attacker to traverse
directories and access files outside the intended web root directory.
The issue was identified and reported through the DWF (Distributed
Weakness Filing) project, which assigns CVE identifiers for
security vulnerabilities.
A directory traversal vulnerability exists in
guard-livereload before version 2.5.2.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guard-Livereload