CVE-2022-25895: lite-dev-server vulnerable to Directory Traversal
(updated )
All versions of package lite-dev-server is vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
References
Code Behaviors & Features
Detect and mitigate CVE-2022-25895 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →