Description
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309120
Related Vulnerabilities
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.12
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core
CVE-2019-5437 Vulnerability in npm package harp
CVE-2023-26107 Vulnerability in npm package sketchsvg
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify