sitemap is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
65
Medium Risk
Affected versions of this package are vulnerable to a path traversal attack due to insufficient input validation in destinationDir and publicBasePath parameters, where the code fails to check for path traversal sequences, block null bytes and malicious characters, and prevent directory escape while allowing absolute paths. This flaw enables attackers to craft malicious inputs that bypass intended restrictions, potentially allowing them to access or modify sensitive files outside the designated directory, leading to information disclosure or system compromise.
You are affected if you are using a version that falls within the vulnerable range.
sitemap is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 7.0.0 - 8.0.2.
Upgrade the sitemap library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant