GHSA-4w62-cq5r-5mmq
GitHub Security Advisory
express-cart unrestricted file upload vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Affected Packages
npm
express-cart
Affected versions:
0
(fixed in 1.1.7)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 30, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.