senchalabs/connect

senchalabs/connect

Releases230
Frequency2 weeks 6 hours
Last Release
Stars9.89K
Connect is an extensible HTTP server framework for node using "plugins" known as middleware.

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.