Description
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312889
Related Vulnerabilities
CVE-2020-8137 Vulnerability in npm package fastify
CVE-2021-21353 Vulnerability in npm package pug
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury
CVE-2020-8441 Vulnerability in maven package org.jyaml:jyaml