Send
by Send Project
npm: send
Source repositories
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-8859 | Med | 0.28 | 5.3 | 0.05 | Jan 23, 2017 | The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors. | ||
| CVE-2024-43799 | Med | 0.26 | 5.0 | 0.01 | Sep 10, 2024 | Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0. |
- risk 0.28cvss 5.3epss 0.05
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
- risk 0.26cvss 5.0epss 0.01
Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.