Svenstaro maintains a focused portfolio centered on the miniserve utility, a lightweight file-serving tool where the observed vulnerability pattern centers on file-access control issues including improper link resolution and time-of-check time-of-use race conditions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Svenstaro over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67124MEDIUM A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended uploa | Jan 23, 2026 | 6.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Svenstaro.
Media articles that mention a CVE ID that affects a product developed by Svenstaro — matched by CVE ID, not by vendor name.