CVE-2026-90494: restify node-restify static.js serveStatic path traversal
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the npm/node-restify package are affected if they use the serveStatic function in /lib/plugins/static.js. The available information states that versions up to 12.0.0 are affected.
Can this be exploited remotely without credentials or user interaction?
Yes. The reported CVSS vector indicates network access, low attack complexity, no privileges required, and no user interaction required.
What is the likely impact of successful exploitation?
The reported impact is limited to confidentiality. A path traversal issue in serveStatic may allow unauthorized access to files reachable through the affected static-file handling path; no integrity or availability impact is reported.
Is a vendor fix available?
The supplied information does not identify a fixed version or vendor response. It states that the vendor was contacted early but did not respond.