Mcstatic Project maintains a focused static file-serving utility where the durable vulnerability signal centers on path-traversal weaknesses that arise from improper pathname validation and directory-access controls. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mcstatic Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3730HIGH mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path. | Jun 7, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-16482HIGH A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending sla | Feb 1, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mcstatic Project.
Media articles that mention a CVE ID that affects a product developed by Mcstatic Project — matched by CVE ID, not by vendor name.