Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2018-1109 Vulnerability in npm package braces
CVE-2021-23358 Vulnerability in maven package org.webjars.bower:underscore
CVE-2021-22135 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-35491 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind