Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2020-6422 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.mergewith
CVE-2023-2507 Vulnerability in npm package clevertap-cordova
CVE-2020-8141 Vulnerability in maven package org.webjars.bowergithub.olado:dot
CVE-2023-26477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui