Description
open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/open-device
https://nodesecurity.io/advisories/447
Related Vulnerabilities
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2019-10747 Vulnerability in maven package org.webjars.npm:set-value
CVE-2022-39243 Vulnerability in maven package com.zaxxer:nuprocess
CVE-2023-30547 Vulnerability in npm package vm2
CVE-2015-0265 Vulnerability in maven package org.apache.ranger:ranger