GHSA-xw79-hhv6-578c
UNKNOWNVersions of serve prior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package does not encode output, allowing attackers to execute arbitrary JavaScript in the victim's browser if user-supplied input is rendered.
- Affected
- >=0, <10.0.2
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2020-09-11
- Source
- osv