CVE-2018-3747: Public.js Project Public.js

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.

Affected products

Published 2018-07-03. Last modified 2026-06-17.