Description
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARSCODE-590122
Related Vulnerabilities
CVE-2023-26158 Vulnerability in maven package org.webjars.npm:mockjs
CVE-2021-32808 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2023-26104 Vulnerability in npm package lite-web-server
CVE-2019-5485 Vulnerability in npm package gitlabhook
CVE-2014-0050 Vulnerability in maven package org.apache.tomcat:tomcat-coyote