Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2023-45857 Vulnerability in maven package org.webjars.bowergithub.axios:axios
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2021-25947 Vulnerability in npm package nestie
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:ra-ui-materialui
CVE-2020-7226 Vulnerability in maven package org.cryptacular:cryptacular