Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-cocoapods-plugin
CVE-2020-8237 Vulnerability in maven package org.webjars.npm:json-bigint
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-standalone
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf