CVE-2023-26111 is a directory traversal vulnerability affecting all versions of the @nubosoftware/node-static and node-static packages. It stems from improper file path sanitization within the servePath function's startsWith() method, allowing attackers to access unauthorized files. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, potentially leading to high confidentiality impact. While the EPSS score is low, suggesting a lower likelihood of exploitation compared to most CVEs, the FAUCET Risk Score is moderate at 53/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with typical patterns for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:\@nubosoftware\/node-static_project:\@nubosoftware\/node-static:-:*:*:*:*:node.js:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:node-static_project:node-static:-:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.