Description
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
Remediation
References
https://gist.github.com/lirantal/9ccdfda0edcb95e36d07a04b0b6c2db0
https://security.snyk.io/vuln/SNYK-JS-SERVELITE-3149916
Related Vulnerabilities
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-1000282 Vulnerability in npm package haraka
CVE-2020-28469 Vulnerability in maven package org.webjars.bowergithub.es128:glob-parent
CVE-2019-10785 Vulnerability in npm package dojox
CVE-2020-7709 Vulnerability in maven package org.webjars.npm:json-pointer