node-srv is vulnerable to local file inclusion due to lack of url validation, which allows a malicious user to read content of any file with known path.
id: CVE-2018-3714
info:
name: node-srv - Local File Inclusion
author: madrobot
severity: medi
...