{"id":"CVE-2024-49770","summary":"oak's path traversal allows transfer of hidden files within the served root directory","details":"`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version 17.1.3, this can be bypassed by encoding `/` as its URL encoded form `%2F`. For an attacker this has potential to read sensitive user data or to gain access to server secrets. Version 17.1.3 fixes the issue.","aliases":["GHSA-qm92-93fv-vh7m"],"modified":"2026-08-12T03:30:40.216387342Z","published":"2024-11-01T16:16:29.482Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49770.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-22","CWE-35"]},"references":[{"type":"WEB","url":"https://github.com/oakserver/oak/blob/3896fe568b25ac0b4c5afbf822ff8344c3d1712a/send.ts#L117-L125"},{"type":"WEB","url":"https://github.com/oakserver/oak/blob/3896fe568b25ac0b4c5afbf822ff8344c3d1712a/send.ts#L182C10-L182C25"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49770.json"},{"type":"ADVISORY","url":"https://github.com/oakserver/oak/security/advisories/GHSA-qm92-93fv-vh7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49770"},{"type":"FIX","url":"https://github.com/oakserver/oak/commit/4b2f27efd5cba5a45b2c3982e610da3af0869209"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oakserver/oak","events":[{"introduced":"0"},{"fixed":"4b2f27efd5cba5a45b2c3982e610da3af0869209"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"17.1.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v17.1.2","v17.1.1","v17.1.0","v17.0.0","v16.1.0","v16.0.0","v15.0.0","14.2.0","v14.1.1","v14.1.0","v14.0.0","v13.2.5","13.2.4","v13.2.3","v13.2.2","v13.2.1","v13.2.0","v13.1.0","v13.0.1","v13.0.0","v12.6.2","v12.6.1","v12.6.0","v12.5.0","v12.4.0","v12.3.1","v12.3.0","v12.2.0","v12.1.0","v12.0.1","v12.0.0","v11.1.0","v11.0.0","v10.6.0","v10.5.1","v10.5.0","v10.4.0","v10.3.0","v10.2.1","v10.2.0","v10.1.1","v10.1.0","v10.0.0","v9.0.1","v9.0.0","v8.0.0","v7.7.0","v7.6.3","v7.6.2","v7.6.1","v7.6.0","v7.5.0","v7.4.1","v7.4.0","v7.3.0","v7.2.0","v7.1.0","v7.0.0","v6.5.1","v6.5.0","v6.4.2","v6.4.1","v6.4.0","v6.3.2","v6.3.1","v6.3.0","v6.2.0","v6.1.0","v6.0.2","v6.0.1","v6.0.0","v5.4.0","v5.3.1","v5.3.0","v5.2.0","v5.1.1","v5.1.0","v5.0.0","v4.0.0","v3.7.0","v3.6.0","v3.5.0","v3.4.0","v3.3.0","v3.2.0","v3.1.0","v3.0.0","v2.10.0","v2.9.0","v2.8.0","v2.7.0","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49770.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}