Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2022-2421 Vulnerability in npm package socket.io-parser
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-cocoapods-plugin
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net
CVE-2020-8134 Vulnerability in npm package ghost
CVE-2021-43797 Vulnerability in maven package io.netty:netty-codec-http