Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2022-2932 Vulnerability in npm package mobiledoc-dom-renderer
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2022-25926 Vulnerability in npm package window-control
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2017-3201 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer