GHSA-2mf3-mr2r-r4vf: @rhinostone/swig: arbitrary local file read via include/extends path traversal
Arbitrary local file disclosure (confidentiality). An attacker able to influence an include / extends / import path — directly, or via untrusted locals — can read files outside the template directory: application configuration, credentials, source code, /etc/passwd, and so on. There is no integrity or availability impact.
References
Code Behaviors & Features
Detect and mitigate GHSA-2mf3-mr2r-r4vf with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →