Description
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/311218
Related Vulnerabilities
CVE-2023-40346 Vulnerability in maven package io.jenkins.plugins:shortcut-job
CVE-2022-45143 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-25940 Vulnerability in npm package lite-server
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2021-41038 Vulnerability in npm package @theia/plugin-ext