Description
Versions of atompm prior to 0.8.2 are vulnerable to Unauthorized File Access. The package fails to sanitize relative paths in the URL for file downloads, allowing attackers to download arbitrary files from the system.
Recommendation
Update the atompm package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.8.2
- Patched version(s): 0.8.2
References
Related Issues
- Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler - CVE-2025-27098
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
- esbuild allows arbitrary file read when running the development server on Windows - Vulnerability
- react-native-mmkv Insertion of Sensitive Information into Log File vulnerability - CVE-2024-21668
You might also like:
- Tags:
- npm
- atompm
Anything's wrong? Let us know Last updated on January 09, 2023


