Description
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
Remediation
References
https://github.com/Foddy/node-red-contrib-huemagic/issues/217
Related Vulnerabilities
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2020-28450 Vulnerability in npm package decal
CVE-2021-23397 Vulnerability in npm package @ianwalter/merge
CVE-2021-26539 Vulnerability in maven package org.webjars.npm:sanitize-html
CVE-2023-30531 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder