All node-static versions

node-static @0.7.11

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
93
Risk Score
MIT
License
No
Install Scripts
3
Dependencies
2
Dev Dependencies
10.5 KB
Package Size
Published

simple, compliant file streaming module for node

Maintainers

cloudheadindexzerophstc

Keywords

httpstaticfileserver

Dependencies (3)

PackageConstraintRegistry Status
mime ^1.2.9 auto_approved
colors >=0.6.0 auto_approved
optimist >=0.3.4 auto_approved

Dev Dependencies (2)

PackageConstraintRegistry Status
vows latest auto_approved
request latest No greenflagged match

Transitive Dependency Tree

5 transitive deps max depth 2
  ├─ colors >=0.6.0 → 1.4.0
  ├─ mime ^1.2.9 → 1.6.0
├─ optimist >=0.3.4 → 0.6.1
  ├─ minimist ~0.0.1
  ├─ wordwrap ~0.0.2 → 0.0.2

Risk Dispositions (2 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
osv:GHSA-5g97-whc9-8g7j osv reject AI AI (osv): Directory traversal CVE affects all versions <= 0.7.11 with no fix published; verdict generalizes to all current and future versions until a patched release appears.
osv:GHSA-8r4g-cg4m-x23c osv reject AI AI (osv): DoS via null bytes affects all versions <= 0.7.11 with no fix published; verdict generalizes across versions.

SAST Findings (3)

HIGH GHSA-5g97-whc9-8g7j: node-static and @nubosoftware/node-static vulnerable to Directory Traversal osv

CVSS 7.5 (HIGH) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N node-static and its fork, @nubosoftware/node-static, are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

MEDIUM GHSA-8r4g-cg4m-x23c: Denial of Service in node-static osv

All versions of node-static are vulnerable to a Denial of Service. The package fails to catch an exception when user input includes null bytes. This allows attackers to access `http://host/%00` and crash the server.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 93. Findings: 2 critical (+80), 1 medium (+10), 1 low (+3), 1 info (+0).

Commit: e59fe21dffbe Browse source

Published to npm: