Harp is a static web server and build tool with a narrow product focus, where its vulnerability disclosures center on information-disclosure and file-access weaknesses such as directory-listing exposure, path traversal, and improper link resolution. These patterns reflect the file-serving and asset-handling scope inherent to a lightweight web platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harpjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5438MEDIUM Path traversal using symlink in npm harp module versions <= 0.29.0. | May 10, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-5437MEDIUM Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable version | May 10, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harpjs.
Media articles that mention a CVE ID that affects a product developed by Harpjs — matched by CVE ID, not by vendor name.