Description
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/312907
Related Vulnerabilities
CVE-2021-23639 Vulnerability in npm package md-to-pdf
CVE-2020-28501 Vulnerability in npm package es6-crawler-detect
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-12432 Vulnerability in maven package net.bull.javamelody:javamelody-core