Vulnerability GHSA-8hfj-j24r-96c4

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
April 04, 2022 at 09:25 PM UTC
Path Traversal: 'dir/../../filename' in moment.locale
1.0.0 - 2.29.1
1.0.0 - 2.29.1

Summary

Path Traversal: 'dir/../../filename' in moment.locale

Details

Impact

This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.

Patches

This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).

Workarounds

Sanitize user-provided locale name before passing it to moment.js.

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
4 years ago
April 04, 2022 at 09:25 PM UTC
Fixed (2.29.2)
4 years ago
April 03, 2022 at 01:18 PM UTC
Fixed (2.29.2)
4 years ago
April 03, 2022 at 01:32 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:49 AM UTC