{"id":"CVE-2020-36629","aliases":["GHSA-p8j8-wxvp-h695"],"url":"https://o3.security/vulnerability/CVE-2020-36629","summary":"SimbCo httpster vulnerable to Path Traversal","details":"A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the patch is d3055b3e30b40b65d30c5a06d6e053dffa7f35d0. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216748.","published":"2022-12-25T11:15:10.840Z","modified":"2026-07-08T05:56:26.174402844Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"httpster","fixedVersion":"1.1.0"}],"fix":{"url":"https://github.com/SimbCo/httpster/commit/d3055b3e30b40b65d30c5a06d6e053dffa7f35d0","label":"SimbCo/httpster@d3055b3"},"references":[{"type":"ADVISORY","url":"https://vuldb.com/?id.216748"},{"type":"FIX","url":"https://github.com/SimbCo/httpster/commit/d3055b3e30b40b65d30c5a06d6e053dffa7f35d0"},{"type":"FIX","url":"https://github.com/SimbCo/httpster/pull/36"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:56:26.174402844Z"}}