Medium severity6.5NVD Advisory· Published Feb 13, 2023· Updated Jun 17, 2026
CVE-2022-25937
CVE-2022-25937
Description
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in CVE-2018-3715.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancenpm | < 3.0.9 | 3.0.9 |
Affected products
3- glance/glancedescription
Patches
Vulnerability mechanics
References
5- github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabacnvdPatchWEB
- security.snyk.io/vuln/SNYK-JS-GLANCE-3318395nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-3hjh-5hgx-f5whghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25937ghsaADVISORY
- gist.github.com/lirantal/c8cfb0398c78e558b7d4ac02aae67809ghsaWEB
News mentions
0No linked articles in our index yet.