Description
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312889
Related Vulnerabilities
CVE-2020-7613 Vulnerability in npm package clamscan
CVE-2022-24437 Vulnerability in npm package git-pull-or-clone
CVE-2020-36049 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate
CVE-2020-7238 Vulnerability in maven package io.netty:netty-all