Description
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINSERVER-590123
Related Vulnerabilities
CVE-2023-27562 Vulnerability in npm package n8n
CVE-2022-25354 Vulnerability in npm package set-in
CVE-2023-38507 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2020-28168 Vulnerability in npm package axios
CVE-2021-33611 Vulnerability in maven package org.webjars.bowergithub.vaadin:vaadin-menu-bar