Description
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
Remediation
References
https://hackerone.com/reports/316346
Related Vulnerabilities
CVE-2023-35147 Vulnerability in maven package org.jenkins-ci.plugins:aws-codecommit-trigger
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2020-28270 Vulnerability in npm package object-hierarchy-access
CVE-2016-5003 Vulnerability in maven package org.apache.xmlrpc:xmlrpc