Description
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572892
Related Vulnerabilities
CVE-2023-22893 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2022-21667 Vulnerability in npm package @soketi/soketi
CVE-2022-23712 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-28249 Vulnerability in npm package joplin
CVE-2016-10735 Vulnerability in maven package ua.mobius.media:bootstrap