Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2019-0193 Vulnerability in maven package org.apache.solr:solr-dataimporthandler
CVE-2022-22138 Vulnerability in npm package fast-string-search
CVE-2021-34079 Vulnerability in npm package docker-tester
CVE-2017-16175 Vulnerability in npm package ewgaddis.lab6
CVE-2018-16479 Vulnerability in npm package http-live-simulator