GHSA-w259-7x22-fr4jMediumCVSS 5.3

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic...

Published
September 13, 2026
Last Modified
September 13, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

🔗 References (6)