Description
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312918
Related Vulnerabilities
CVE-2022-1440 Vulnerability in npm package git-interface
CVE-2020-7691 Vulnerability in maven package org.webjars.npm:jspdf
CVE-2015-6584 Vulnerability in maven package org.webjars.bower:datatables
CVE-2018-1002200 Vulnerability in maven package org.codehaus.plexus:plexus-archiver
CVE-2023-31716 Vulnerability in npm package @frangoteam/fuxa