Nbluis develops a static file-serving application that presents a narrow but focused vulnerability surface centered on path-traversal flaws in directory restriction logic. The durable signal reflects the product's role as a web-accessible file server and the inherent risks of pathname validation in file-access boundaries; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nbluis over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26152HIGH All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js. | Oct 3, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nbluis.
Media articles that mention a CVE ID that affects a product developed by Nbluis — matched by CVE ID, not by vendor name.