Intel

AIKIDO-2025-10767

sitemap is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 6, 2025

65

Medium Risk

This Affects:

JSsitemap
7.0.0 - 8.0.2
Fixed in 9.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a path traversal attack due to insufficient input validation in destinationDir and publicBasePath parameters, where the code fails to check for path traversal sequences, block null bytes and malicious characters, and prevent directory escape while allowing absolute paths. This flaw enables attackers to craft malicious inputs that bypass intended restrictions, potentially allowing them to access or modify sensitive files outside the designated directory, leading to information disclosure or system compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sitemap is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 7.0.0 - 8.0.2.

How to fix this

Upgrade the sitemap library to the patch version.