High severity7.5NVD Advisory· Published Jan 30, 2023· Updated Jun 17, 2026
CVE-2022-25936
CVE-2022-25936
Description
Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
servstnpm | < 2.0.3 | 2.0.3 |
Affected products
3- servst/servstdescription
Patches
Vulnerability mechanics
References
5- github.com/andrepolischuk/servst/commit/f7cae5d2d7c64c86bc512e1e50614240396ef114nvdPatchThird Party AdvisoryWEB
- gist.github.com/lirantal/691d02d607753d54856f9335f9a1692fnvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-SERVST-3244896nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-88v8-v46g-6c9wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25936ghsaADVISORY
News mentions
0No linked articles in our index yet.