CVE-2024-43800: Openjsf Serve-Static
Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Affected products
- Openjsf Serve-Static: before 1.16.0 (fixed in 1.16.0); from 2.0.0, before 2.1.0 (fixed in 2.1.0)
Published 2024-09-10. Last modified 2026-06-17.