Description
Registering serve-index on a production Express route lets requesters browse directory listings. Backup files, configuration, logs, or source maps left in a static root may expose internal structure and sensitive filenames.
Potential impact
- Exposure of internal directory structure and filenames
- Easier discovery and potential downloading of backup, log, or configuration files
- Reconnaissance using exposed filenames and versions
Remediation
- Do not register
serve-indexin production. - Serve only a dedicated public directory through
express.static. - Expose required files through explicit routes or index files.
- Remove backup files, logs, configuration, and source maps from deployment artifacts.
Examples
Before
javascript
const express = require('express');
const serveIndex = require('serve-index');
const app = express();
app.use('/files', serveIndex('public/files'));
After
javascript
const express = require('express');
const app = express();
app.use('/assets', express.static('public'));
app.get('/files', (req, res) => res.status(403).end());
Explanation:
- Before: Registering
serve-indexlets requesters browse the directory's file list. - After: The production application does not register
serve-index.