Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2019-10785 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox
CVE-2020-7701 Vulnerability in npm package madlib-object-utils
CVE-2020-36377 Vulnerability in npm package aaptjs
CVE-2021-34080 Vulnerability in npm package ssl-utils
CVE-2021-31522 Vulnerability in maven package org.apache.kylin:kylin-server-base