CVE-2022-25895

HIGH

lite-dev-server - Path Traversal via req.url Input

Title source: llm
STIX 2.1

Description

All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

Scores

CVSS v3 7.5
EPSS 0.0145
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
lite-dev-server_project/lite-dev-server
npm/lite-dev-server 0npm
Published Dec 21, 2022
Tracked Since Feb 18, 2026