Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2020-28481 Vulnerability in npm package socket.io
CVE-2014-0050 Vulnerability in maven package org.apache.jackrabbit:oak-run
CVE-2021-34428 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2017-16184 Vulnerability in npm package scott-blanch-weather-app
CVE-2023-34660 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent