Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2020-28501 Vulnerability in npm package es6-crawler-detect
CVE-2020-28451 Vulnerability in npm package image-tiler
CVE-2022-38369 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2022-2079 Vulnerability in npm package nocodb
CVE-2022-39350 Vulnerability in npm package @dependencytrack/frontend