Vulnerabilities (CVE)

Filtered by vendor Openjsf Subscribe
Filtered by product Serve-static
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-43800 1 Openjsf 1 Serve-static 2024-09-20 N/A 4.7 MEDIUM
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.