CVE-2014-3744: Node.js
High severity, CVSS 7.5. EPSS: 34% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
Affected products
- Node.js Node.js: up to and including 0.2.4
Published 2017-10-23. Last modified 2026-06-17.