DevDocs serves files from a local directory. The filename parameter isn't sanitised — traverse outside the intended folder and read arbitrary files from the server.