Description
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/yzt
https://nodesecurity.io/advisories/416
Related Vulnerabilities
CVE-2022-23082 Vulnerability in maven package io.whitesource:curekit
CVE-2023-37949 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2021-23700 Vulnerability in npm package merge-deep2
CVE-2022-26183 Vulnerability in npm package pnpm
CVE-2020-11023 Vulnerability in maven package org.webjars.npm:jquery