All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
History

Mon, 27 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2023-05-10T05:00:01.474Z

Updated: 2025-01-27T18:38:31.700Z

Reserved: 2023-02-20T10:28:48.924Z

Link: CVE-2023-26126

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.616Z

cve-icon NVD

Status : Modified

Published: 2023-05-10T05:15:08.860

Modified: 2025-01-27T19:15:14.747

Link: CVE-2023-26126

cve-icon Redhat

No data.