react-on-rails is vulnerable to Path Traversal
60
Medium Risk
Affected versions of this package are vulnerable to Arbitrary File Read via Path Traversal due to improper validation of the server_bundle_output_path that allows an attacker to break out of the intended directory. By exploiting this flaw, an attacker could potentially read sensitive files from anywhere on the filesystem that the application has access to, using directory traversal sequences (e.g., ../../etc/passwd) in the path configuration, leading to an information disclosure vulnerability or further exploitation.
You are affected if you are using a version that falls within the vulnerable range.
react-on-rails is vulnerable to Path Traversal in versions 11.0.8 - 16.0.1.
Upgrade the react-on-rails library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant