github.com
https://github.com/firebase/superstatic/blob/v5.0.1/lib/providers/fs.js GHSA-WM77-Q74P-5763
Path Traversal in superstatic
Description
Affected of `superstatic` are vulnerable to path traversal when used on Windows. Additionally, it is vulnerable to path traversal on other platforms combined with certain Node.js versions which erroneously normalize `\\` to `/` in paths on all platforms (a known example being Node.js v9.9.0). ## Recommendation Update to version 5.0.2 or later.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
superstaticBrowse npm / superstatic | GitHub Advisory | Before 5.0.2 · Fixed in 5.0.2 | affected |
References
4github.com
https://github.com/firebase/superstatic/commit/e396ff62f588732989137d6c40d46b310e51ef2b github.com
https://github.com/firebase/superstatic/pull/255 npmjs.com
https://www.npmjs.com/advisories/652