CVE-2015-8859: Send Project Send

Medium severity, CVSS 5.3. EPSS: 4.7% chance of exploitation in the next 30 days.

The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.

Affected products

Published 2017-01-23. Last modified 2026-10-08.