Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2022-43427 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2017-0931 Vulnerability in npm package html-janitor
CVE-2020-7596 Vulnerability in npm package codecov
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel__traverse
CVE-2018-14041 Vulnerability in maven package org.webjars:bootstrap