Description
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://nodesecurity.io/advisories/436
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/picard
Related Vulnerabilities
CVE-2022-35924 Vulnerability in npm package next-auth
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2018-12536 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2019-18818 Vulnerability in npm package strapi
CVE-2022-31172 Vulnerability in npm package @openzeppelin/contracts-upgradeable