richardgirges/express-fileupload

richardgirges/express-fileupload

Releases49
Frequency2 months 3 days
Last Release
Stars1.56K
Simple express file upload middleware that wraps around busboy

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH7.5 HIGH

This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.