Description
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARKEDTREE-590121
Related Vulnerabilities
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.components:codemirror
CVE-2019-10795 Vulnerability in maven package org.webjars.npm:undefsafe
CVE-2011-3190 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror