serverless-framework-config-exposure: Serverless Framework - Configuration Exposure

2026-10-08 PoC Public

Description

A Serverless Framework configuration file (serverless.yml) was found exposed on the web server. The file describes the service, cloud provider, functions and often provider level environment variables, IAM statements and plugin settings, which can disclose the application architecture and occasionally hardcoded secrets to an unauthenticated visitor.

PoC

id: serverless-framework-config-exposure

info:
  name: Serverless Framework - Configuration Exposure
  author: ChrisJr404
  severity: medium
  description: |
    A Serverless Framework configuration file (serverless.yml) was found exposed on the web server. The file describes the service, cloud provider, functions and often provider level environment variables, IAM statements and plugin settings, which can disclose the application architecture and occasionally hardcoded secrets to an unauthenticated visitor.
  reference:
    - https://www.serverless.com/framework/docs/providers/aws/guide/serverless.yml
    - https://www.serverless.com/framework/docs/providers/aws/guide/functions
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
  metadata:
    max-request: 2
    google-query: intitle:"index of" "serverless.yml"
  tags: exposure,config,serverless,iac,aws

http:
  - method: GET
    path:
      - "{{BaseURL}}/serverless.yml"
      - "{{BaseURL}}/serverless.yaml"

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "service:"
          - "provider:"
          - "functions:"
        condition: and

      - type: word
        part: header
        words:
          - "text/html"
        negative: true

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        part: body
        group: 1
        regex:
          - 'service:\s*([a-zA-Z0-9_-]+)'
# digest: 490a00463044022064059644afbdbcc1df5017890383277474837125ba27ba5ad70a269bafb01b27022070994c4dea4ff22567b6016ee7ee591929015daba32a6dc49bed95da68619dac:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.