Description
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312889
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror
CVE-2022-23458 Vulnerability in maven package org.webjars.bowergithub.nhn:tui.grid
CVE-2020-11022 Vulnerability in maven package org.webjars.npm:jquery
CVE-2021-21696 Vulnerability in maven package org.jenkins-ci.main:jenkins-core