VYPR

H3

by Npm

CVEs (1)

  • CVE-2026-86253Sep 6, 2026
    risk 0.00cvss epss

    h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization.…