Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2018-3721 Vulnerability in npm package lodash._basemerge
CVE-2021-26541 Vulnerability in npm package gitlog
CVE-2022-39381 Vulnerability in npm package muhammara
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2021-23353 Vulnerability in maven package org.webjars.bower:jspdf