Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2020-15174 Vulnerability in npm package electron
CVE-2016-10547 Vulnerability in npm package nunjucks
CVE-2022-21222 Vulnerability in maven package org.webjars.npm:css-what
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-14061 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind