npx-server@0.0.40 vulnerabilities

No dependency, single file/script http server

Direct Vulnerabilities

Known vulnerabilities in the npx-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

npx-server is a simple HTTP server with autoindexing of directories, custom (one file) controllers system which logic is, reloading without reloading server, reloading browser (hotloader) if one of files on the hard drive changed, everything shipped in one .js file with no dependencies and one command installation.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) which allows to embed HTML in filenames.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for npx-server.

*