Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2020-22755 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-29252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2022-23223 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2020-13822 Vulnerability in npm package elliptic
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webmvc