crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-3733.json"