Description
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
Remediation
References
https://github.com/xudafeng/startserver/blob/bef0c4e4d21da42a40ce87cf25fd54ac8d8cb2d8/lib/index.js%23L71
https://snyk.io/vuln/SNYK-JS-STARTSERVER-1296388
Related Vulnerabilities
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http
CVE-2023-45820 Vulnerability in npm package directus
CVE-2021-23664 Vulnerability in npm package @isomorphic-git/cors-proxy
CVE-2018-1000632 Vulnerability in maven package dom4j:dom4j
CVE-2023-28155 Vulnerability in maven package org.webjars.npm:request