Description
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
Remediation
References
https://vuldb.com/?id.158745
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572886
Related Vulnerabilities
CVE-2015-0254 Vulnerability in maven package javax.servlet.jsp.jstl:jstl
CVE-2020-4038 Vulnerability in maven package org.webjars.npm:graphql-playground-html
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement
CVE-2022-38369 Vulnerability in maven package org.apache.iotdb:iotdb-server