Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2020-8203 Vulnerability in npm package @sailshq/lodash
CVE-2023-24188 Vulnerability in maven package com.bstek.ureport:ureport2-core
CVE-2017-16114 Vulnerability in maven package org.webjars:marked
CVE-2020-15126 Vulnerability in npm package parse-server
CVE-2021-39147 Vulnerability in maven package com.thoughtworks.xstream:xstream