Summary
guard-livereload has a directory traversal vulnerability
Advisory details
The vulnerability allows remote attackers to read arbitrary files on the server by exploiting improper path validation in the livereload server functionality.
This vulnerability is related to the handling of file paths in the livereload server component, which could allow an attacker to traverse directories and access files outside the intended web root directory.
The issue was identified and reported through the DWF (Distributed Weakness Filing) project, which assigns CVE identifiers for security vulnerabilities.
A directory traversal vulnerability exists in guard-livereload before version 2.5.2.
References
- https://github.com/advisories/GHSA-g65v-27r3-5p6m
- https://github.com/guard/guard-livereload/issues/159
- https://github.com/guard/guard-livereload/pull/158
- https://github.com/guard/guard-livereload/commit/0e98469e6b9d81a5bd415781534a23d087c271f8
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/guard-livereload/CVE-2016-1000305.yml
- https://security.snyk.io/vuln/SNYK-RUBY-GUARDLIVERELOAD-20361
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
- HIGHCVE-2026-75914
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
- HIGHCVE-2026-69086
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
- MEDIUMCVE-2026-61625
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
- MEDIUMCVE-2026-75602
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
- MEDIUMGHSA-gw25-m53r-qh88
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)