Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. simplehttpserver
  4. ›
  5. GMS-2018-23

GMS-2018-23: Cross Site Scripting

February 26, 2018

simplehttpserver allows embedding HTML in file names, which in certain conditions allows execution of malicious JavaScript.

References

  • hackerone.com/reports/309648

Code Behaviors & Features

Detect and mitigate GMS-2018-23 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.1

Solution

There is no solution for this vulnerability at the moment and the author removed the package from NPM. Use another module with similar functionality.

Source file

npm/simplehttpserver/GMS-2018-23.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:16 +0000.