MEDIUM5.4
GHSA-jrhj-2j3q-xf3v
Stored Cross-Site Scripting in simplehttpserver
Quick fix
GHSA-jrhj-2j3q-xf3v — simplehttpserver: upgrade to the fixed version with the command below.
npm install simplehttpserver@0.1.0Details
Simplehttpserver prior to version 0.1.0 are vulnerable to stored cross-site scripting (XSS). To be exploited an attacker needs to control the filename of a file that is used in the directory listing output. This version is patched in 0.1.0
Are you affected?
Enter the version of the package you're using.