GHSA-jrhj-2j3q-xf3v
GitHub Security Advisory
Stored Cross-Site Scripting in simplehttpserver
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Simplehttpserver prior to version 0.1.0 are vulnerable to stored cross-site scripting (XSS). To be exploited an attacker needs to control the filename of a file that is used in the directory listing output. This version is patched in 0.1.0
Affected Packages
npm
simplehttpserver
Affected versions:
0
(fixed in 0.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:05 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.