Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2021-21141 Vulnerability in npm package electron
CVE-2021-32730 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2020-28168 Vulnerability in maven package org.webjars.bowergithub.axios:axios
CVE-2021-28168 Vulnerability in maven package org.glassfish.jersey.core:jersey-common