Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2021-21175 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-39381 Vulnerability in npm package hummus
CVE-2023-41592 Vulnerability in npm package froala-editor
CVE-2023-45135 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-war
CVE-2023-29207 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates