Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2022-36921 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2018-1999024 Vulnerability in maven package org.webjars.npm:mathjax
CVE-2021-46364 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-2230 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-6886 Vulnerability in maven package com.xnx3.wangmarket:wangmarket