npm package intelligence

node-red-contrib-huemagic Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package node-red-contrib-huemagic, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting node-red-contrib-huemagic
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
node-red-contrib-huemagic KEVs with sensor-observed exploitation activity

Review node-red-contrib-huemagic exploitation against the versions you run

One of the one exploited node-red-contrib-huemagic vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested node-red-contrib-huemagic vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2021-25864

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an...

Beyond CISA 26 Jan 2021

Recurring weakness patterns

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') account for mapped occurrences across this node-red-contrib-huemagic KEV portfolio.

Browse all KEVs →