Description
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
Remediation
References
https://vuldb.com/?id.158745
https://snyk.io/vuln/SNYK-JS-FASTHTTP-572886
Related Vulnerabilities
CVE-2019-16542 Vulnerability in maven package org.jenkins-ci.plugins:anchore-container-scanner
CVE-2015-8855 Vulnerability in maven package org.webjars.bower:semver
CVE-2020-15242 Vulnerability in npm package next
CVE-2016-10696 Vulnerability in npm package windows-latestchromedriver
CVE-2020-36186 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind