{"id":"GHSA-xw79-hhv6-578c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xw79-hhv6-578c","summary":"Cross-Site Scripting in serve","details":"Versions of `serve` prior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package does not encode output, allowing attackers to execute arbitrary JavaScript in the victim's browser if user-supplied input is rendered.\n\n\n## Recommendation\n\nUpgrade to version 10.0.2 or later.","published":"2020-09-11T21:16:59Z","modified":"2021-09-28T16:54:33Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"serve","fixedVersion":"10.0.2"}],"fix":{"url":"https://github.com/zeit/serve-handler/commit/65b4d4183a31a8076c78c40118acb0ca1b64f620","label":"zeit/serve-handler@65b4d41"},"references":[{"type":"WEB","url":"https://github.com/zeit/serve-handler/commit/65b4d4183a31a8076c78c40118acb0ca1b64f620"},{"type":"WEB","url":"https://hackerone.com/reports/358641"},{"type":"WEB","url":"https://hackerone.com/reports/398285"},{"type":"PACKAGE","url":"https://github.com/zeit/serve-handler"},{"type":"WEB","url":"https://www.npmjs.com/advisories/971"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T16:54:33Z"}}