Description
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/311218
Related Vulnerabilities
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api
CVE-2020-7688 Vulnerability in npm package mversion
CVE-2022-25908 Vulnerability in npm package create-choo-electron
CVE-2020-28469 Vulnerability in maven package org.webjars.npm:glob-parent
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes