Description
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router
https://nodesecurity.io/advisories/352
Related Vulnerabilities
CVE-2019-10806 Vulnerability in npm package vega-util
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2022-25860 Vulnerability in npm package simple-git
CVE-2018-16330 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-jdbc