Description
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
Remediation
References
https://hackerone.com/reports/334837
Related Vulnerabilities
CVE-2022-3971 Vulnerability in npm package matrix-appservice-irc
CVE-2020-28458 Vulnerability in maven package org.webjars.bower:datatables.net
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15on
CVE-2018-20227 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-util