hfs@0.52.9 vulnerabilities

HTTP File Server

Direct Vulnerabilities

Known vulnerabilities in the hfs package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
OS Command Injection

hfs is a HTTP File Server

Affected versions of this package are vulnerable to OS Command Injection via the improper use of execSync instead of spawnSync for executing shell commands.

How to fix OS Command Injection?

Upgrade hfs to version 0.52.10 or higher.

<0.52.10