NodeRED-Dashboard before 2.26.2 is vulnerable to local file inclusion because it allows ui_base/js/..%2f directory traversal to read files.
View the template here CVE-2021-3223.yaml
References:
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2