CVE-2020-7681

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/07/2020
Last modified:
27/07/2020

Description

This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:indo-mars:marscode:*:*:*:*:*:node.js:*:*


References to Advisories, Solutions, and Tools