CVE-2018-3726: Crud-File-Server Project Crud-File-Server
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
Affected products
- Crud-File-Server Project Crud-File-Server: before 0.8.0 (fixed in 0.8.0)
Published 2018-06-07. Last modified 2026-06-17.