Description
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
Remediation
References
https://hackerone.com/reports/695416
Related Vulnerabilities
CVE-2020-28434 Vulnerability in npm package gitblame
CVE-2019-10796 Vulnerability in npm package rpi
CVE-2022-38752 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-21290 Vulnerability in maven package io.netty:netty-codec-http
CVE-2023-6293 Vulnerability in npm package sequelize-typescript