CVE-2023-26152: Nbluis Static-Server

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

Affected products

  • Nbluis Static-Server: up to and including 3.0.0

Published 2023-10-03. Last modified 2026-06-17.