Path Traversal in public
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Sep 3, 2020 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
Description
        Reviewed
      Aug 31, 2020 
    
  
        Published to the GitHub Advisory Database
      Sep 3, 2020 
    
  
        Last updated
      Jan 9, 2023 
    
  
All versions of
publicare vulnerable to Path Traversal. This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.Recommendation
No fix is currently available. Do not use
publicin production or consider using an alternative module until a fix is made available.References