Impact
fastify-cli, a command‑line tool for running Fastify applications, starts the Node.js Inspector when a debugging flag is supplied. The implementation fails to honor the user‑supplied bind address, instead binding the Inspector to a broadly reachable network interface. Because the Inspector protocol permits arbitrary code evaluation, a remote party that can reach the exposed address can execute code on the developer’s machine. This flaw is a classic example of remote code execution via a debugging interface (CWE‑1327).
Affected Systems
The vulnerability affects all releases of fastify-cli from version 1.5.0 through 8.0.1. Users should upgrade to version 8.0.1, which correctly respects the configured Inspector bind address and limits exposure to the intended loopback interface.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. No EPSS score is available, but the absence of a KEV listing does not mitigate the risk because the flaw can be exploited without a public exploit. Attackers who can reach the debugging port that was unintentionally bound to a public interface could immediately obtain remote code execution. The likelihood of exploitation is significant if the debugging interface is exposed, especially in environments where the service is reachable from external networks.
OpenCVE Enrichment