Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| rendertron(npm) | 0 | 1.1.0 | N/A |
CVSS Metrics