Description
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/311218
Related Vulnerabilities
CVE-2021-38384 Vulnerability in npm package serverless-offline
CVE-2023-47321 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2018-16487 Vulnerability in npm package lodash._basemerge
CVE-2022-25349 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2019-12728 Vulnerability in maven package org.grails:grails-core