CVE-2018-16493
Path Traversal in simplehttpserver
EPSS 0.61%
Description
Versions of `simplehttpserver` prior to 0.2.1 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. ## Recommendation Upgrade to version 0.2.1 or later.
How to fix CVE-2018-16493
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/static-resource-server—no fix listed
Is CVE-2018-16493 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, <= 1.7.2