Description
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
Remediation
References
https://hackerone.com/reports/360727
Related Vulnerabilities
CVE-2019-10773 Vulnerability in npm package yarn
CVE-2021-23391 Vulnerability in npm package calipso
CVE-2021-22060 Vulnerability in maven package org.springframework:spring-core
CVE-2022-44310 Vulnerability in npm package ecdh
CVE-2010-1622 Vulnerability in maven package org.springframework:spring-core