shape-idea
Audited by Socket on Sep 28, 2026
2 alerts found:
Anomalyx2This is a simple static file server and contains no evidence of malware, credential theft, persistence, or unauthorized network activity. It has a path traversal containment weakness caused by prefix matching, allowing access to certain sibling paths whose names begin with the configured root. Replace the check with a boundary-safe comparison, such as verifying file === root or file.startsWith(root + path.sep), preferably after path.resolve. Binding explicitly to 127.0.0.1 would also reduce unintended exposure for a development server.
The code appears to be a benign static HTTP file server and contains no clear malware or supply-chain backdoor behavior. It has a potentially exploitable path containment flaw because startsWith(root) is not a reliable directory-boundary check after path traversal normalization. Replace it with path.resolve and a path.relative-based containment check, and avoid serving sensitive files from the document root.