Description
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/311218
Related Vulnerabilities
CVE-2019-19935 Vulnerability in npm package froala-editor
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service
CVE-2021-32808 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2022-1330 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js