GHSA-cv3v-7846-6pxmHighCVSS 7.5Disclosed before NVD

Unauthorized File Access in node-git-server

Published
September 3, 2020
Last Modified
July 17, 2026

📋 Description

Versions of node-git-server prior to 0.6.1 are vulnerable to Unauthorized File Access. It is possible to access any git repository by using absolute paths, which may allow attackers to access private repositories.

Recommendation

Upgrade to version 0.6.1 or later.

🎯 Affected products1

  • npm/node-git-server:>= 0.2.0, < 0.6.1

🔗 References (7)