Description
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.0
References
Related Issues
- node-forge has ASN.1 Unbounded Recursion - CVE-2025-66031
- Deserialization of Untrusted Data in bson - CVE-2020-7610
- Cross-site scripting in bootstrap-select - CVE-2019-20921
- XSS vulnerability that affects bootstrap - CVE-2018-20676
- Tags:
- npm
- serve-lite
Anything's wrong? Let us know Last updated on January 30, 2023