Vendorsserve-static projectserve-staticany version
Vulnerabilities

serve-static project serve-static for Node.js any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2015-1164
Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.
Published 2015-01-21 · Modified
4.3EPSS 0.026