fig. 01 — GHSA-g8m7-qhv7-9h5x, the advisory selected below
// advisories
GHSA-g8m7-qhv7-9h5x
HIGH
Versions of serve-here.js prior to 1.2.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.