Path traversal in CureKit
High severity
GitHub Reviewed
Published
Jun 1, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
May 31, 2022
Published to the GitHub Advisory Database
Jun 1, 2022
Reviewed
Jun 3, 2022
Last updated
Jan 27, 2023
CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function
isFileOutsideDir
fails to sanitize the user input which may lead to path traversal.References