There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-5418.json"