Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2018-11776 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-43859 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2018-3721 Vulnerability in maven package org.webjars:lodash
CVE-2021-39234 Vulnerability in maven package org.apache.ozone:ozone-common
CVE-2019-10785 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox