CVE-2020-7684: Rollup-Plugin-Serve Project Rollup-Plugin-Serve

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.

Affected products

Published 2020-07-17. Last modified 2026-06-17.