Description
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572892
Related Vulnerabilities
CVE-2020-8137 Vulnerability in maven package org.webjars.npm:uppy
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_2.13
CVE-2021-39135 Vulnerability in npm package @npmcli/arborist
CVE-2021-25914 Vulnerability in npm package object-collider
CVE-2020-27428 Vulnerability in npm package scratch-svg-renderer