Description
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
Remediation
References
https://vuldb.com/?id.158745
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572886
Related Vulnerabilities
CVE-2019-5438 Vulnerability in npm package harp
CVE-2020-1953 Vulnerability in maven package org.apache.commons:commons-configuration2
CVE-2021-3312 Vulnerability in maven package org.opencms:opencms-core
CVE-2021-3189 Vulnerability in npm package slashify
CVE-2022-40149 Vulnerability in maven package org.codehaus.jettison:jettison