CVE-2023-3348

MEDIUM

Wrangler <=3.1.0/2.20.1 - Path Traversal

Title source: llm
STIX 2.1

Description

The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.

Scores

CVSS v3 5.7
EPSS 0.0024
EPSS Percentile 47.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
cloudflare/wrangler < 3.1.1
npm/wrangler 0 - 2.20.1npm
Published Aug 03, 2023
Tracked Since Feb 18, 2026