Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2022-3171 Vulnerability in maven package com.google.protobuf:protobuf-javalite
CVE-2020-7611 Vulnerability in maven package io.micronaut:micronaut-http-client
CVE-2019-10744 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-15362 Vulnerability in npm package wifiscanner
CVE-2022-24279 Vulnerability in npm package madlib-object-utils