### [CVE-2019-5457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5457) ![](https://img.shields.io/static/v1?label=Product&message=min-http-server&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-site%20Scripting%20(XSS)%20-%20Stored%20(CWE-79)&color=brighgreen) ### Description Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. ### POC #### Reference - https://hackerone.com/reports/570568 - https://hackerone.com/reports/570568 #### Github No PoCs found on GitHub currently.