npm package report

Is nhouston safe?

1 known vulnerability.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


      cvss
      not scored

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 74th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-44g9-w23c-5rw7, the advisory selected below

      // 1 advisories

      GHSA-44g9-w23c-5rw7

      UNKNOWNCVE-2014-8883

      All versions of the static file server module nhouston are vulnerable to directory traversal. An attacker can provide input such as ../ to read files outside of the served directory.

      // recommendation

      It is recommended that a different module be used, as we have been unable to reacher the maintainer of this module. We will continue to reach out to them, and if an update becomes available that fixes the issue, we will update this advisory accordingly.


      Checked 2026-10-04 at 01:14 UTC. The most recent advisory here was published 2020-08-31. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.