Intel

AIKIDO-2024-10032

hexo is vulnerable to Path Traversal

Path TraversalCVE-2023-39584 Published Apr 18, 2024

75

High Risk

This Affects:

JShexo
0.0.1 - 7.1.1
Fixed in 7.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to directory traversal through Hexo's file reading functionality. An attacker can access arbitrary files by manipulating the file path input, using special characters like ".." and "/" separators.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hexo is vulnerable to Path Traversal in versions 0.0.1 - 7.1.1.

How to fix this

Upgrade the hexo library to the patch version.