Directory traversal in rollup-plugin-server
High severity
GitHub Reviewed
Published
Jul 29, 2020
to the GitHub Advisory Database
•
Updated Sep 5, 2023
Description
Reviewed
Jul 29, 2020
Published to the GitHub Advisory Database
Jul 29, 2020
Last updated
Sep 5, 2023
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in
readFile
operation inside thereadFileFromContentBase
function.References