Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2022-25916 Vulnerability in npm package mt7688-wiscan
CVE-2019-12041 Vulnerability in maven package org.webjars.npm:remarkable
CVE-2017-18349 Vulnerability in maven package com.alibaba:fastjson
CVE-2023-39013 Vulnerability in maven package no.priv.garshol.duke:duke