Description
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/badjs-sourcemap-server
https://nodesecurity.io/advisories/349
Related Vulnerabilities
CVE-2021-32831 Vulnerability in npm package total.js
CVE-2022-24785 Vulnerability in npm package moment
CVE-2020-7733 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2023-26136 Vulnerability in npm package tough-cookie
CVE-2022-25869 Vulnerability in maven package org.webjars.bower:angular