miniserve
Activity
- Latest release
- 5mo ago
- Total releases
- 54
- Cadence
- ~38 days
- Last 12 months
- 3
Details
- License
- MIT
- First release
- May 16, 2018
| Version | Released | |
|---|---|---|
0.35.0
unknown
|
0.35.0
unknown
Dependencies (54)
+ 46 more |
|
0.34.0
unknown
|
0.34.0
unknown
Dependencies (54)
+ 46 more |
|
0.33.0
unknown
|
0.33.0
unknown
Dependencies (54)
+ 46 more |
|
0.32.0
unknown
|
0.32.0
unknown
Dependencies (54)
+ 46 more |
|
0.31.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.31.0
unknown
Dependencies (53)
+ 45 more |
|
0.30.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.30.0
unknown
Dependencies (53)
+ 45 more |
|
0.29.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.29.0
unknown
Dependencies (51)
+ 43 more |
|
0.28.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.28.0
unknown
Dependencies (49)
+ 41 more |
|
0.27.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.27.1
unknown
Dependencies (50)
+ 42 more |
|
0.27.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.27.0
unknown
Dependencies (50)
+ 42 more |
|
0.26.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.26.0
unknown
Dependencies (50)
+ 42 more |
|
0.25.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.25.0
unknown
Dependencies (49)
+ 41 more |
|
0.24.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.24.0
unknown
Dependencies (49)
+ 41 more |
|
0.23.2
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.23.2
unknown
Dependencies (50)
+ 42 more |
|
0.23.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.23.1
unknown
Dependencies (50)
+ 42 more |
|
0.23.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.23.0
unknown
Dependencies (50)
+ 42 more |
|
0.22.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.22.0
unknown
Dependencies (51)
+ 43 more |
|
0.21.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.21.0
unknown
Dependencies (49)
+ 41 more |
|
0.20.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.20.0
unknown
Dependencies (48)
+ 40 more |
|
0.19.5
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.5
unknown
Dependencies (48)
+ 40 more |
|
0.19.4
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.4
unknown
Dependencies (48)
+ 40 more |
|
0.19.3
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.3
unknown
Dependencies (48)
+ 40 more |
|
0.19.2
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.2
unknown
Dependencies (48)
+ 40 more |
|
0.19.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.1
unknown
Dependencies (47)
+ 39 more |
|
0.19.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.19.0
unknown
Dependencies (47)
+ 39 more |
|
0.18.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.18.0
unknown
Dependencies (46)
+ 38 more |
|
0.17.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.17.0
unknown
Dependencies (46)
+ 38 more |
|
0.16.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.16.0
unknown
Dependencies (47)
+ 39 more |
|
0.15.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.15.0
unknown
Dependencies (44)
+ 36 more |
|
0.14.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (41)
+ 33 more |
|
0.13.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (41)
+ 33 more |
|
0.12.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.12.1
unknown
Dependencies (40)
+ 32 more |
|
0.12.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.12.0
unknown
Dependencies (40)
+ 32 more |
|
0.11.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.11.0
unknown
Dependencies (40)
+ 32 more |
|
0.10.4
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.10.4
unknown
Dependencies (37)
+ 29 more |
|
0.10.3
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.10.3
unknown
Dependencies (37)
+ 29 more |
|
0.10.2
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.10.2
unknown
Dependencies (37)
+ 29 more |
|
0.10.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.10.1
unknown
Dependencies (37)
+ 29 more |
|
0.10.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.10.0
unknown
Dependencies (37)
+ 29 more |
|
0.9.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.9.0
unknown
Dependencies (36)
+ 28 more |
|
0.8.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.8.0
unknown
Dependencies (37)
+ 29 more |
|
0.7.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (34)
+ 26 more |
|
0.6.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (33)
+ 25 more |
|
0.5.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (33)
+ 25 more |
|
0.4.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.4.1
unknown
Dependencies (24)
+ 16 more |
|
0.4.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (24)
+ 16 more |
|
0.3.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (15)
+ 7 more |
|
0.3.0
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (11)
+ 3 more |
|
0.2.2
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.2.2
unknown
Dependencies (8)
|
|
0.2.1
unknown
1 CVE
CVE-2025-67124
GHSA-mxc8-4jqf-368q
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Medium
Network
High
None
None
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume). Fixed in
0.32.0
References Updated Feb 03, 2026 · Source: OSV.dev |
0.2.1
unknown
Dependencies (8)
|