All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url
user input that is passed to the server code.
{ "github_reviewed": true, "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed_at": "2022-12-21T17:22:17Z", "nvd_published_at": "2022-12-21T05:15:00Z" }