CVE-2022-25936

HIGH

servst < 2.0.3 - Path Traversal via Improper File Path Sanitization

Title source: llm
STIX 2.1

Description

Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.

Scores

CVSS v3 7.5
EPSS 0.0155
EPSS Percentile 81.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
npm/servst 0 - 2.0.3npm
servst_project/servst < 2.0.3
Published Jan 30, 2023
Tracked Since Feb 18, 2026