MEDIUM6.1
GHSA-pwq7-f7f9-cm2j
Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload
Details
dutchcoders Transfer.sh versions 1.4.0 and prior are vulnerable to Cross Site Scripting (XSS) via a malicious document uploaded in transfer.sh. There is a fix commit merged into [main](https://github.com/dutchcoders/transfer.sh/commit/31ad4e01e158497519f8680c187e1ceb8594c59d) for this issue, but an updated version has not yet been released.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dutchcoders/transfer.sh
Introduced in:
0No fixed version published yet for github.com/dutchcoders/transfer.sh (go modules). Pin to a known-safe version or switch to an alternative.