Loading HuntDB...

GHSA-5rc4-8qqh-vq7f

GitHub Security Advisory

vercel/serve allows access to restricted files if filename is URL encoded.

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

Affected Packages

npm serve
Affected versions: 0 (fixed in 6.5.2)

Related CVEs

Key Information

GHSA ID
GHSA-5rc4-8qqh-vq7f
Published
August 9, 2021 10:24 PM
Last Modified
September 12, 2023 8:58 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
serve
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.