Description
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
Remediation
References
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572886
https://vuldb.com/?id.158745
Related Vulnerabilities
CVE-2017-18077 Vulnerability in npm package brace-expansion
CVE-2019-10305 Vulnerability in maven package com.xebialabs.xl-deploy:jenkins-dependendencies
CVE-2016-10592 Vulnerability in npm package jser-stat
CVE-2018-20843 Vulnerability in npm package dbus
CVE-2023-30525 Vulnerability in maven package org.jenkins-ci.plugins:reportportal