Medium severity5.3NVD Advisory· Published Jan 23, 2017· Updated Jun 17, 2026
CVE-2015-8859
CVE-2015-8859
Description
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sendnpm | < 0.11.1 | 0.11.1 |
Affected products
2Patches
Vulnerability mechanics
References
9- nodesecurity.io/advisories/56nvdBroken LinkPatchVendor Advisory
- www.openwall.com/lists/oss-security/2016/04/20/11nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/96435nvdBroken LinkThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-jgqf-hwc5-hh37ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-8859ghsaADVISORY
- github.com/expressjs/serve-static/blob/master/HISTORY.mdghsaWEB
- github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aedghsaWEB
- github.com/pillarjs/send/pull/70ghsaWEB
- web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435ghsaWEB
News mentions
0No linked articles in our index yet.