Medium severity6.1NVD Advisory· Published Jun 1, 2018· Updated Jun 17, 2026
CVE-2018-3755
CVE-2018-3755
Description
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with element used in directory name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sexstaticnpm | <= 0.6.2 | — |
Affected products
4cpe:2.3:a:sexstatic_project:sexstatic:0.6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sexstatic_project:sexstatic:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:sexstatic_project:sexstatic:0.6.2:*:*:*:*:*:*:*
- HackerOne/sexstaticv5Range: <=0.6.2
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/328210nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-qfh2-6f7q-gr86ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-3755ghsaADVISORY
- www.npmjs.com/advisories/671ghsaWEB
News mentions
0No linked articles in our index yet.