npm package report

Is serve-handler safe?

1 known vulnerability, worst severity MODERATE.

// reach

12 direct dependencies

3 carry known advisories, worst HIGH

6 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


cvss
0.0
medium

severity band, no base score published

epss
not scored

chance of exploitation in 30 days

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-9vhv-p9r7-rm53, the advisory selected below

// 1 advisories

GHSA-9vhv-p9r7-rm53

MODERATE

Serve Handler, before 5.0.3, has a XSS via HTML tag injection in directory lisiting page.


Checked 2026-10-04 at 01:08 UTC. The most recent advisory here was published 2021-02-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.