Low severityNVD Advisory· Published Oct 8, 2014· Updated May 6, 2026
CVE-2014-6394
CVE-2014-6394
Description
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sendnpm | < 0.8.4 | 0.8.4 |
Affected products
8- cpe:2.3:a:apple:xcode:7.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
Patches
19c6ca9b2c0b8Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
18- github.com/visionmedia/send/commit/9c6ca9b2c0b880afd3ff91ce0d211213c5fa5f9anvdExploitWEB
- github.com/advisories/GHSA-xwg4-93c6-3h42ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-6394ghsaADVISORY
- lists.apple.com/archives/security-announce/2015/Sep/msg00002.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2014-October/139938.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2014-October/140020.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2014-September/139415.htmlnvdWEB
- secunia.com/advisories/62170nvdWEB
- www-01.ibm.com/support/docview.wssnvdWEB
- www.openwall.com/lists/oss-security/2014/09/24/1nvdWEB
- www.openwall.com/lists/oss-security/2014/09/30/10nvdWEB
- www.securityfocus.com/bid/70100nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/96727nvdWEB
- github.com/visionmedia/send/pull/59nvdWEB
- support.apple.com/HT205217nvdWEB
- www.npmjs.com/advisories/32ghsaWEB
- nodesecurity.io/advisories/send-directory-traversalnvd
News mentions
0No linked articles in our index yet.