Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2022-25895 Vulnerability in npm package lite-dev-server
CVE-2020-7641 Vulnerability in npm package grunt-util-property
CVE-2020-8129 Vulnerability in npm package script-manager
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2021-3312 Vulnerability in maven package org.opencms:opencms-core