GHSA-rch9-xh7r-mqgw
GitHub Security Advisory
Cross-Site Scripting in connect
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Affected Packages
npm
connect
Affected versions:
0
(fixed in 2.14.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 2, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.