Description
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
Remediation
References
https://gist.github.com/lirantal/5550bcd0bdf92c1b56fbb20e141fe5bd
https://security.snyk.io/vuln/SNYK-JS-STATICDEVSERVER-3149917
Related Vulnerabilities
CVE-2023-0835 Vulnerability in npm package markdown-pdf
CVE-2022-24289 Vulnerability in maven package org.apache.cayenne:cayenne-server
CVE-2022-41966 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:oap-server