Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2021-23463 Vulnerability in maven package com.h2database:h2
CVE-2020-36320 Vulnerability in maven package com.vaadin:vaadin-server
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.web
CVE-2020-7629 Vulnerability in npm package install-package
CVE-2020-7633 Vulnerability in npm package apiconnect-cli-plugins