Description
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
Remediation
References
https://nodesecurity.io/advisories/89
Related Vulnerabilities
CVE-2021-26707 Vulnerability in npm package merge-deep
CVE-2020-9498 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2017-16223 Vulnerability in npm package nodeaaaaa
CVE-2020-7775 Vulnerability in npm package freediskspace
CVE-2020-15138 Vulnerability in maven package org.webjars:prismjs