Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
cvss
0.0
critical
severity band, no base score published
epss
not scored
chance of exploitation in 30 days
xyz score
0.0
medium
CyberXYZ composite out of 10
fig. 01 — GHSA-f3vw-587g-r29g, the advisory selected below
// 1 advisories
GHSA-f3vw-587g-r29g
CRITICAL
Versions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded ../.