CVE-2018-16475
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.8%
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
In short
Knightjs versions up to 0.0.1 have a path traversal vulnerability that lets attackers read any file on the server by manipulating file paths in requests.
Technical detail
A path traversal flaw (CWE-22) in Knightjs ≤0.0.1 permits unauthenticated attackers to access arbitrary files on the server through specially crafted path inputs that bypass directory restrictions, resulting in unauthorized information disclosure.
Summary generated and translated by AI from the official description.
A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.
Affected products
npm · knightjsReferences
https://hackerone.com/reports/403707