This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Matteo Collina
nodeland.dev
did:plc:2q7mnid6di5sxgzzpsdvdu47
GHSA-m8rv-5g2x-5cg5 (medium): a malicious `type` on a duck-typed blob-like request body could inject CRLF into the `content-type` header on HTTP/1.1.
Values are now coerced and validated before they reach the header. All three lines.
https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
2026-07-29T15:21:07.875Z