CVE-2023-26126

HIGH

m.static < 2.2.0 - Path Traversal via requestFile Function

Title source: llm
STIX 2.1

Description

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0065
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
m.static_project/m.static < 2.2.0
npm/m.static 0npm
Published May 10, 2023
Tracked Since Feb 18, 2026