Description
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARKEDTREE-590121
Related Vulnerabilities
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2023-48087 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap
CVE-2019-10249 Vulnerability in maven package org.eclipse.xtext:org.eclipse.xtext.maven.parent
CVE-2021-23353 Vulnerability in maven package org.webjars.npm:jspdf