CVE-2018-3718: Zeit Serve

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

Affected products

  • Zeit Serve: before 6.5.2 (fixed in 6.5.2)

Published 2018-06-07. Last modified 2026-06-17.