← back
CVE-2018-16473CWE-22

CVE-2018-16473

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.4%
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
nono source reports it
In short

The takeapeek module up to version 0.2.2 has a flaw that lets attackers browse and list files and folders on the server that they shouldn't have access to. This happens because the module doesn't properly check file paths before accessing them.

Technical detail

A path traversal vulnerability (CWE-22) in takeapeek <=0.2.2 permits unauthenticated directory and file enumeration through improper input validation on file path parameters. An attacker can exploit this by crafting requests with directory traversal sequences (e.g., ../) to access files outside the intended directory scope, potentially exposing sensitive information.

Summary generated and translated by AI from the official description.
A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
Affected products
npm · takeapeek