Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2022-41710 Vulnerability in npm package electron-markdownify
CVE-2020-15500 Vulnerability in npm package tileserver-gl
CVE-2016-10541 Vulnerability in maven package org.webjars.npm:shell-quote
CVE-2022-22963 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-core
CVE-2021-39133 Vulnerability in maven package org.rundeck:rundeck