CVE-2024-56198 Information

Description

path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0 the filters can be bypassed using .=%5c which results in a path traversal. This vulnerability is fixed in 3.1.0.

Reference

https://github.com/cabraviva/path-sanitizer/commit/b6d2319eac910dffdfacc8460f5b5cc5a1518ead https://github.com/cabraviva/path-sanitizer/security/advisories/GHSA-94p5-r7cc-3rpr https://www.loom.com/share/b766ece5193842848ce7562fcd559256?sid=fd826eb6-0eee-4601-bf0e-9cfee5c56e9d

Share on: