All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
Products Affected
| Vendor | Product | Version |
|---|---|---|
| serve-lite_project | serve-lite | * |
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Products Affected
| Vendor | Product | Version |
|---|---|---|
| serve-lite_project | serve-lite | * |