CVE-2018-3725 describes a Path Traversal vulnerability in the hekto node module, allowing an unauthenticated attacker to read arbitrary files on the system due to insufficient input validation. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a severe impact with high confidentiality risk and no integrity or availability impact. While no public exploits or active exploitation have been observed, and community discussion is minimal, organizations using the hekto module should be aware of this potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.0CPE matchmatch criteria | cpe:2.3:a:hekto_project:hekto:0.2.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.