Relative Path Traversal Attack on note creation - An attacker can read arbitrary .md files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path traversal
https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-p528-555r-pf87