Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| geddy(npm) | 0 | 13.0.8 | N/A |
CVSS Metrics