Description
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
Remediation
References
https://hackerone.com/reports/316346
Related Vulnerabilities
CVE-2021-37713 Vulnerability in npm package tar
CVE-2020-7634 Vulnerability in npm package heroku-addonpool
CVE-2021-3805 Vulnerability in npm package object-path
CVE-2022-24785 Vulnerability in maven package org.fujion.webjars:moment
CVE-2018-21270 Vulnerability in maven package org.webjars.npm:stringstream