The path traversal bug allows attackers to include arbitrary filesystem content in generated PDFs when file paths are not properly validated.
A flaw in the binary-parser npm package before version 2.3.0 lets attackers execute arbitrary JavaScript via unsanitized ...