Description
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router
https://nodesecurity.io/advisories/352
Related Vulnerabilities
CVE-2023-25827 Vulnerability in maven package net.opentsdb:opentsdb
CVE-2022-24718 Vulnerability in npm package @finastra/ssr-pages
CVE-2022-39251 Vulnerability in npm package matrix-js-sdk
CVE-2023-49293 Vulnerability in npm package vite
CVE-2023-50100 Vulnerability in maven package com.jfinal:jfinal