Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| send(npm) | 0 | 0.19.0 | N/A |
CVSS Metrics