Description
All versions of snekserve are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s browser through files with names containing malicious code.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Related Issues
- Stimulsoft Dashboard.JS Cross Site Scripting vulnerability - stimulsoft-dashboards-js - CVE-2024-24397
- CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection - CVE-2024-24815
- RSSHub Cross-site Scripting vulnerability caused by internal media proxy - CVE-2024-27926
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
You might also like:
- Tags:
- npm
- snekserve
Anything's wrong? Let us know Last updated on January 09, 2023


