CVE-2019-5437: Harpjs Harp
Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Affected products
- Harpjs Harp: up to and including 0.29.0
Published 2019-05-10. Last modified 2026-06-17.