Description
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312907
Related Vulnerabilities
CVE-2020-14968 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2021-32808 Vulnerability in npm package ckeditor4
CVE-2021-43807 Vulnerability in maven package org.opencastproject:opencast-common
CVE-2019-10808 Vulnerability in npm package utilitify
CVE-2022-28367 Vulnerability in maven package org.owasp.antisamy:antisamy