Description
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MARKEDTREE-590121
Related Vulnerabilities
CVE-2023-51079 Vulnerability in maven package org.mvel:mvel2
CVE-2010-2273 Vulnerability in npm package dojo
CVE-2022-25853 Vulnerability in npm package semver-tags
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core