Description
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572892
Related Vulnerabilities
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2007-6433 Vulnerability in maven package org.jboss.seam:jboss-seam
CVE-2021-21254 Vulnerability in npm package @ckeditor/ckeditor5-markdown-gfm
CVE-2023-22899 Vulnerability in maven package net.lingala.zip4j:zip4j
CVE-2018-11694 Vulnerability in maven package org.webjars.npm:node-sass