Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2017-16147 Vulnerability in npm package shit-server
CVE-2023-26115 Vulnerability in npm package word-wrap
CVE-2021-32859 Vulnerability in maven package org.webjars.npm:github-com-baremetrics-calendar
CVE-2018-6561 Vulnerability in maven package org.webjars.npm:dijit
CVE-2022-28156 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest