CVE-2015-8859: Send Project Send
Medium severity, CVSS 5.3. EPSS: 4.7% chance of exploitation in the next 30 days.
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
Affected products
- Send Project Send: before 0.11.1 (fixed in 0.11.1)
Published 2017-01-23. Last modified 2026-10-08.