npm package report

Is restify safe?

1 known vulnerability, worst severity MODERATE.

// reach

0 direct dependencies

none carry a known advisory

    3 packages depend on it

    an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


    cvss
    0.0
    medium

    severity band, no base score published

    epss
    0.00%
    medium

    chance of exploitation in 30 days, 60th percentile of all CVEs

    xyz score
    not scored

    CyberXYZ composite out of 10

    fig. 01 — GHSA-qw3g-35hc-fcrh, the advisory selected below

    // 1 advisories

    GHSA-qw3g-35hc-fcrh

    MODERATECVE-2017-16018

    Affected versions of restify are susceptible to a cross-site scripting vulnerability when using URL encoded script tags in a non-existent URL.

    // proof of concept:

    Request

    https://localhost:3000/no5_such3_file7.pl?%22%3E%3Cscript%3Ealert(73541);%3C/script%3E

    Will be included in response:

    ## Recommendation
    
    Update to version 4.1.0 or later.
    // cvss v3.0 vector

    CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

    Attack vector
    Network
    Attack complexity
    Low
    Privileges required
    None
    User interaction
    Required
    Scope
    Changed
    Confidentiality
    Low
    Integrity
    Low
    Availability
    None

    Checked 2026-10-04 at 01:08 UTC. The most recent advisory here was published 2018-11-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.