{"id":"CVE-2021-3223","aliases":["GHSA-2hw7-mxvj-m455"],"url":"https://o3.security/vulnerability/CVE-2021-3223","summary":"Path traversal in Node-RED-Dashboard","details":"Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.","published":"2021-01-26T18:16:28.757Z","modified":"2026-07-08T21:26:54.386693Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"node-red-dashboard","fixedVersion":"2.26.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/node-red/node-red-dashboard/issues/669"},{"type":"ADVISORY","url":"https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:26:54.386693Z"}}