Executive brief
snekserve is a Node.js package used for serving files. All versions are vulnerable to stored Cross-Site Scripting (XSS) because the package fails to sanitize filenames, allowing attackers to inject malicious code that executes in users' browsers when files with specially crafted names are accessed. This can lead to session hijacking, credential theft, or malware distribution.</exec_brief> <parameter name="technical_details">The vulnerability is a stored Cross-Site Scripting (CWE-79) flaw in snekserve's filename handling mechanism. The package fails to properly sanitize or encode filenames before rendering them in responses, allowing attackers to upload or reference files with HTML/JavaScript payloads in the filename itself. When a victim's browser accesses or views the directory listing containing the malicious filename, the JavaScript executes in the context of the application domain. No authentication or special preconditions are required; any user able to create or reference files on the server can exploit this. No patch is currently available.</details> <parameter name="severity">high
Affected products
- snekserve snekserve all versions
Timeline
- 2020-09-03: disclosed