{"id":"CVE-2021-3223","aliases":["GHSA-2hw7-mxvj-m455"],"url":"https://o3.security/vulnerability/CVE-2021-3223","summary":"Path traversal in Node-RED-Dashboard","details":"In Node-RED-Dashboard before 2.26.2 there is a path traversal vulnerability. It allows ui_base/js/..%2f directory traversal to read files.","published":"2021-01-26T18:16:28.757Z","modified":"2026-07-08T21:26:54.386693Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"node-red-dashboard","fixedVersion":"2.26.2"}],"fix":{"url":"https://github.com/node-red/node-red-dashboard/commit/f48f356df966f607ba3d09c27396074b81f2ae97","label":"node-red/node-red-dashboard@f48f356"},"references":[{"type":"ADVISORY","url":"https://github.com/node-red/node-red-dashboard/issues/669"},{"type":"ADVISORY","url":"https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3223"},{"type":"WEB","url":"https://github.com/node-red/node-red-dashboard/commit/f48f356df966f607ba3d09c27396074b81f2ae97"},{"type":"WEB","url":"https://www.npmjs.com/package/node-red-dashboard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:26:54.386693Z"}}