7.5
CVSSv3

CVE-2022-21192

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().

Vulnerable Product Search on Vulmon Subscribe to Product

serve-lite project serve-lite