Description
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572892
Related Vulnerabilities
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2022-38752 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-3804 Vulnerability in npm package taro
CVE-2022-25645 Vulnerability in maven package org.webjars.npm:dset
CVE-2022-36910 Vulnerability in maven package org.jenkins-ci.plugins:lucene-search