VDB
Sign up
MEDIUM5.4

GHSA-gmxv-xf2q-6j8m

Cross-Site Scripting in m-server

Quick fix

GHSA-gmxv-xf2q-6j8m — m-server: upgrade to the fixed version with the command below.

npm install m-server@1.4.2

Details

Versions of `m-server` before 1.4.2 are vulnerable to stored cross-site scripting. This vulnerability is exploitable if an attacker is able to control the name of a file that `m-server` is serving.

## Recommendation

Update to version 1.4.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/m-server
Introduced in: 0Fixed in: 1.4.2
Fixnpm install m-server@1.4.2

References