Description
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/sencisho
https://nodesecurity.io/advisories/340
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2020-10683 Vulnerability in maven package org.dom4j:dom4j
CVE-2017-16098 Vulnerability in npm package charset
CVE-2019-20920 Vulnerability in npm package handlebars
CVE-2020-8125 Vulnerability in maven package org.webjars.npm:klona