Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2019-5438 Vulnerability in npm package harp
CVE-2022-36313 Vulnerability in maven package org.webjars.npm:file-type
CVE-2023-37963 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator
CVE-2020-7683 Vulnerability in npm package rollup-plugin-server
CVE-2023-34613 Vulnerability in maven package net.sf.sojo:sojo