HIGH
GHSA-xw79-hhv6-578c
Cross-Site Scripting in serve
Quick fix
GHSA-xw79-hhv6-578c — serve: upgrade to the fixed version with the command below.
npm install serve@10.0.2Details
Versions of `serve` prior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package does not encode output, allowing attackers to execute arbitrary JavaScript in the victim's browser if user-supplied input is rendered.
## Recommendation
Upgrade to version 10.0.2 or later.
Are you affected?
Enter the version of the package you're using.