happy-coder is vulnerable to Path Traversal
71
High Risk
Affected versions of this package are vulnerable to Unrestricted File System Access via RPC Handlers, where handlers such as readFile, writeFile, listDirectory, and getDirectoryTree provide authenticated remote clients with complete file system access without path restrictions or sandboxing, allowing the reading and writing of any file the process can access. An attacker who obtains authentication credentials can exploit this to read sensitive files such as SSH keys, exfiltrate private repository contents via getDirectoryTree and readFile calls, write malicious code to startup files like .bashrc, and access AWS credentials, npm tokens, and other sensitive data stored in the user's home directory.
You are affected if you are using a version that falls within the vulnerable range.
happy-coder is vulnerable to Path Traversal in versions 0.10.0 - 0.11.2.
Upgrade the happy-coder library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant