Description
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/311218
Related Vulnerabilities
CVE-2020-7616 Vulnerability in npm package express-mock-middleware
CVE-2019-10769 Vulnerability in npm package safer-eval
CVE-2022-35924 Vulnerability in npm package next-auth
CVE-2017-16114 Vulnerability in maven package org.webjars.npm:marked
CVE-2017-1000190 Vulnerability in maven package org.simpleframework:simple-xml