Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-5688

26
FAUCET Score

CVE-2015-5688 describes a directory traversal vulnerability in Geddy versions prior to 13.0.8, specifically within the lib/app/index.js component, affecting Node.js applications. This flaw allows unauthenticated remote attackers to read arbitrary files on the server by manipulating the PATH_INFO with encoded directory traversal sequences. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring low attack complexity and resulting in partial confidentiality impact. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this Local File Inclusion, and it has a high FAUCET Risk Score of 98/100, indicating significant potential risk despite minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
13.0.7CPE matchmatch criteria
cpe:2.3:a:geddyjs:geddy:13.0.7:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.38%
Probability of exploitation in next 30 days
EPSS Percentile
94.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2015-5688 · Feb 25, 2021
This CVE's current EPSS score of 0.0939 is in the 94th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: geddyFixed in: 13.0.8

Vendor Advisories (1)

npmGHSA-333x-9vgq-v2j4high

Directory Traversal in geddy

Oct 24, 2017

References

github.com / geddy/geddy/commit/2de63b68b3aa6c08848f261ace550a37959ef231
github.com / geddy/geddy/issues/697
ExploitPatch
github.com / geddy/geddy/pull/699
github.com / geddy/geddy/releases/tag/v13.0.8
Patch
nodesecurity.io / advisories/geddy-directory-traversal
Exploit