Releases26
Frequency3 months 2 weeks
Last Release
simple, compliant file streaming module for node

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions, <= 0.7.117.5 HIGH

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.