Medium severity6.1NVD Advisory· Published Jan 6, 2020· Updated Jun 17, 2026
CVE-2019-15602
CVE-2019-15602
Description
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fileviewnpm | <= 0.1.6 | — |
Affected products
3- fileview/fileviewdescription
Patches
Vulnerability mechanics
References
6- hackerone.com/reports/507159nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gvr4-7xgc-gx3wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-15602ghsaADVISORY
- github.com/itworkcenter/fileview/issues/1ghsaWEB
- github.com/itworkcenter/fileview/pull/2ghsaWEB
- www.npmjs.com/advisories/1452ghsaWEB
News mentions
0No linked articles in our index yet.