Description
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
Remediation
References
https://nodesecurity.io/advisories/89
Related Vulnerabilities
CVE-2023-3432 Vulnerability in maven package net.sourceforge.plantuml:plantuml
CVE-2017-16146 Vulnerability in npm package mockserve
CVE-2021-23543 Vulnerability in npm package realms-shim
CVE-2022-25645 Vulnerability in npm package dset
CVE-2023-46495 Vulnerability in npm package @evershop/evershop