{
  "@id": "urn:uuid:0067d198-7c43-43e7-9fff-b59da78545d5",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T19:09:59.945055+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4"
          }
        }
      ],
      "timestamp": "2026-09-24T19:09:59.945055+00:00",
      "status_notes": "Vulnerability CVE-2014-6394 affects version 0.0.4 of send, and is fixed in 0.0.4-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2014-6394"
      },
      "action_statement": "Vulnerability CVE-2014-6394 affects version 0.0.4 of send, and is fixed in 0.0.4-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4"
          }
        }
      ],
      "timestamp": "2026-09-24T19:09:59.945055+00:00",
      "status_notes": "Vulnerability CVE-2015-8859 affects version 0.0.4 of send, and is fixed in 0.0.4-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2015-8859"
      },
      "action_statement": "Vulnerability CVE-2015-8859 affects version 0.0.4 of send, and is fixed in 0.0.4-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4"
          }
        }
      ],
      "timestamp": "2026-09-24T19:09:59.945055+00:00",
      "status_notes": "Vulnerability CVE-2024-43799 does not affect version 0.0.4 of send. not_affected \u2014 Target version 0.0.4 predates the vulnerability. The vulnerable pattern (creating HTML anchor tags with href attributes in redirect responses) was introduced 297 commits later in commit 4698f17 and fixed in v0.19.0. Version 0.0.4 uses simple text output with proper HTML escaping via utils.escape(), containing none of the vulnerable code. The attack chain from URL path input to code execution is...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2024-43799"
      },
      "impact_statement": "not_affected \u2014 Target version 0.0.4 predates the vulnerability. The vulnerable pattern (creating HTML anchor tags with href attributes in redirect responses) was introduced 297 commits later in commit 4698f17 and fixed in v0.19.0. Version 0.0.4 uses simple text output with proper HTML escaping via utils.escape(), containing none of the vulnerable code. The attack chain from URL path input to code execution is..."
    }
  ]
}
