Description
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572892
Related Vulnerabilities
CVE-2023-27095 Vulnerability in maven package cn.hippo4j:hippo4j-core
CVE-2022-24614 Vulnerability in maven package com.drewnoakes:metadata-extractor
CVE-2016-4469 Vulnerability in maven package org.apache.archiva:archiva-webapp
CVE-2022-24760 Vulnerability in npm package parse-server
CVE-2022-0272 Vulnerability in maven package io.gitlab.arturbosch.detekt:detekt-core