Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2020-7746 Vulnerability in npm package chart.js
CVE-2021-28100 Vulnerability in maven package com.netflix.priam:priam
CVE-2021-28164 Vulnerability in maven package org.eclipse.jetty:jetty-webapp
CVE-2022-31070 Vulnerability in npm package @ffdc/nestjs-proxy
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bcprov-jdk18on