VDB
Sign up
MEDIUM6.1

GHSA-pwq7-f7f9-cm2j

Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload

Details

dutchcoders Transfer.sh versions 1.4.0 and prior are vulnerable to Cross Site Scripting (XSS) via a malicious document uploaded in transfer.sh. There is a fix commit merged into [main](https://github.com/dutchcoders/transfer.sh/commit/31ad4e01e158497519f8680c187e1ceb8594c59d) for this issue, but an updated version has not yet been released.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dutchcoders/transfer.sh
Introduced in: 0

No fixed version published yet for github.com/dutchcoders/transfer.sh (go modules). Pin to a known-safe version or switch to an alternative.

References