Description
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
Remediation
References
https://hackerone.com/reports/316346
Related Vulnerabilities
CVE-2021-32855 Vulnerability in npm package vditor
CVE-2022-41714 Vulnerability in npm package fastest-json-copy
CVE-2018-3719 Vulnerability in npm package mixin-deep
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15to18
CVE-2023-34603 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent