Description
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://nodesecurity.io/advisories/352
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router
Related Vulnerabilities
CVE-2022-31172 Vulnerability in npm package @openzeppelin/contracts
CVE-2021-32820 Vulnerability in npm package express-handlebars
CVE-2021-23329 Vulnerability in npm package nested-object-assign
CVE-2021-23820 Vulnerability in npm package json-pointer
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api