MEDIUM6.1
GHSA-h24f-9mm4-w336
Cross-site Scripting (XSS) - Stored in crud-file-server
Quick fix
GHSA-h24f-9mm4-w336 — crud-file-server: upgrade to the fixed version with the command below.
npm install crud-file-server@0.8.0Details
Versions of `crud-file-server` before 0.8.0 are vulnerable to stored cross-site scripting (XSS). This is due to insufficient santiziation of filenames when directory index is served by `crud-file-server`.
## Recommendation
Update to version 0.8.0 or later.
Are you affected?
Enter the version of the package you're using.