Medium severity6.5NVD Advisory· Published Jun 7, 2018· Updated Jun 17, 2026
CVE-2018-3715
CVE-2018-3715
Description
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancenpm | < 3.0.4 | 3.0.4 |
Affected products
3- HackerOne/glance node modulev5Range: Versions before 3.0.4
Patches
Vulnerability mechanics
References
5- github.com/jarofghosts/glance/commit/8cfd88e44ebd3f07e3a2eaf376a3e758b6c4ca19nvdPatchThird Party AdvisoryWEB
- hackerone.com/reports/310106nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-2x4q-6jfv-8h9hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-3715ghsaADVISORY
- www.npmjs.com/advisories/590ghsaWEB
News mentions
0No linked articles in our index yet.