CVE-2022-25895: Lite-Dev-Server Project Lite-Dev-Server
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
Affected products
- Lite-Dev-Server Project Lite-Dev-Server: affected versions not specified
Published 2022-12-21. Last modified 2026-06-17.