Static File Server Vulnerable to Command Injection
CVE-2024-43800
4.7MEDIUM
What is CVE-2024-43800?
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Affected Version(s)
serve-static < 1.16.0 < 1.16.0
serve-static >= 2.0.0, < 2.1.0 < 2.0.0, 2.1.0