CVE-2023-26126 Information
May 11, 2023
cve
Description
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
Reference
https://security.snyk.io/vuln/SNYK-JS-MSTATIC-3244915 https://gist.github.com/lirantal/dcb32c11ce87f5aafd2282b90b4dc998
Share on: