VDB
Sign up
MEDIUM5.4

GHSA-rch9-xh7r-mqgw

Cross-Site Scripting in connect

Quick fix

GHSA-rch9-xh7r-mqgw — connect: upgrade to the fixed version with the command below.

npm install connect@2.14.0

Details

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/connect
Introduced in: 0Fixed in: 2.14.0
Fixnpm install connect@2.14.0

References