MEDIUM
GHSA-cpgr-wmr9-qxv4
Cross-Site Scripting in serve
Quick fix
GHSA-cpgr-wmr9-qxv4 — serve: upgrade to the fixed version with the command below.
npm install serve@10.0.2Details
Versions of `serve` prior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
## Recommendation
Upgrade to version 10.0.2 or later.
Are you affected?
Enter the version of the package you're using.