Node.js before 8.6.0 allows remote attackers to access unintended files because a change to ".." handling is incompatible with the pathname validation used by unspecified community modules.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view