hexo@2.8.0 vulnerabilities

A fast, simple & powerful blog framework, powered by Node.js.

Direct Vulnerabilities

Known vulnerabilities in the hexo package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

hexo is an A fast, simple & powerful blog framework, powered by Node.js.

Affected versions of this package are vulnerable to Directory Traversal via the Hexo's file read functionality. An attacker can read arbitrary files by manipulating the file path input.

Note:

This issue is only exploitable if the attacker has the ability to control the file path input. This vulnerability was only verified successfully in the Windows environment.

How to fix Directory Traversal?

Upgrade hexo to version 7.2.0 or higher.

<7.2.0
  • M
Cross-site Scripting (XSS)

hexo is an A fast, simple & powerful blog framework, powered by Node.js.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The POST body and tags don't sanitize malicious javascript during web page generation. As a result, local unprivileged attacker could inject arbitrary code.

How to fix Cross-site Scripting (XSS)?

Upgrade hexo to version 6.0.0 or higher.

<6.0.0