Http File Server Project develops a lightweight file-serving application whose vulnerability profile centers on path-traversal weaknesses that allow directory-access bypass. This narrow but accessible product presents a durable exposure pattern rooted in insufficient pathname validation in its core serving logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Http File Server Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40668HIGH The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file | Jun 9, 2022 | 8.1 | 26 | NO | NO |
CVE-2019-5458MEDIUM Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim' | Jul 30, 2019 | 5.4 | 20 | NO | NO |
CVE-2019-5447MEDIUM A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders. | Jul 15, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Http File Server Project.
Media articles that mention a CVE ID that affects a product developed by Http File Server Project — matched by CVE ID, not by vendor name.