Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2022-42743 Vulnerability in npm package deep-parse-json
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.convertors
CVE-2019-5438 Vulnerability in npm package harp
CVE-2019-10806 Vulnerability in npm package vega-util
CVE-2018-3737 Vulnerability in maven package org.webjars.npm:sshpk