Junglewise Threat Intelligence

serve Cross-Site Scripting in filename handling

Severity: info · Published 2020-09-11

Technologies: Serve. Vendors: npm.

Executive brief

serve is a lightweight HTTP server commonly used in development workflows to serve static files. The vulnerability allows attackers to execute arbitrary JavaScript in users' browsers by crafting malicious filenames containing embedded scripts. An attacker can trick a user into accessing or downloading a file with a malicious name, leading to session hijacking, credential theft, or malware distribution.

Technical details

The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw in the filename handling mechanism of serve versions prior to 10.0.2. The application fails to properly sanitize or encode filenames when displaying them in directory listings or file responses, allowing attackers to inject malicious JavaScript payloads through crafted filenames. The attack requires a user to access a directory listing or file served by a malicious serve instance, but no authentication is required. An attacker can achieve arbitrary JavaScript execution in the victim's browser context, potentially exfiltrating sensitive data or performing actions on behalf of the user. The fix is available in version 10.0.2 and later.

Affected products

  • serve prior to 10.0.2

Timeline

  • 2020-09-11: disclosed

References

Related threats