CPE
An incomplete fix for CVE-2024-29180 in webpack-dev-middleware allows path traversal via crafted URL requests when publicPath lacks a trailing slash, potentially leading to arbitrary local file read.