Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2022-31167 Vulnerability in maven package org.xwiki.platform:xwiki-platform-security
CVE-2023-24789 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2022-23080 Vulnerability in npm package directus
CVE-2021-42392 Vulnerability in maven package com.h2database:h2
CVE-2021-23597 Vulnerability in npm package fastify-multipart