Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2023-45133 Vulnerability in npm package @babel/traverse
CVE-2015-8862 Vulnerability in maven package org.webjars.bower:mustache
CVE-2021-21165 Vulnerability in npm package electron
CVE-2022-28157 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap