npm vulnerability intelligence

send NPM Package
Vulnerability Check

Better streaming static file server with Range and conditional-GET support

Moderate MIT v1.2.1
Vulnerability Analysis OSV Live

send

v1.2.1 · MIT · 113,256,041 dl/wk

Advisory Breakdown

Critical 0
High 0
Moderate 1
Low 2

Severity Rating

Moderate

3 advisories

Moderate

Weekly downloads

113,256,041

Total advisories

3

Latest version

1.2.1

License

MIT

Known advisories

OSV records for the npm ecosystem

3
GHSA-jgqf-hwc5-hh37 CVE-2015-8859 moderate

Root Path Disclosure in send

Affected: >=0 <0.11.1 Fixed in: 0.11.1 Updated Nov 8, 2023
View source
GHSA-m6fv-jmcg-4jfg CVE-2024-43799 low

send vulnerable to template injection that can lead to XSS

Affected: >=0 <0.19.0 Fixed in: 0.19.0 Updated Feb 4, 2026
View source
GHSA-xwg4-93c6-3h42 CVE-2014-6394 low

Directory Traversal in send

Affected: >=0 <0.8.4 Fixed in: 0.8.4 Updated Nov 8, 2023
View source

Checked Jun 7, 2026, 5:17 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
send
Ecosystem
npm
Latest version
1.2.1
License
MIT
Weekly downloads
113,256,041

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/7/2026, 5:17:38 PM