CVE-2024-43799

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/09/2024
Last modified:
03/11/2025

Description

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:send_project:send:*:*:*:*:*:node.js:*:* 0.19.0 (excluding)