hexo is vulnerable to Path Traversal
75
High Risk
Affected versions of this package are vulnerable to directory traversal through Hexo's file reading functionality. An attacker can access arbitrary files by manipulating the file path input, using special characters like ".." and "/" separators.
You are affected if you are using a version that falls within the vulnerable range.
hexo is vulnerable to Path Traversal in versions 0.0.1 - 7.1.1.
Upgrade the hexo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant