Description
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Patch Now
AI Analysis

Impact

A flaw in the serveStatic method of restify node-restify versions up to 12.0.0 allows a remote attacker to craft a request path that includes traversal sequences and cause the server to serve files outside the intended static directory. This is a CWE-22 on the host file system, exposing sensitive data. The vulnerability description code; the impact is limited to information disclosure.

Affected Systems

All installations of restify node-restify 12.0.0 or earlier that use the serveStatic plugin in /lib/plugins/static.js. Any Node.js application that incorporates this static middleware is affected.

Risk and Exploitability

The CVSS score of 6.9 reflects moderate severity, while the EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread exploitation to date. However a standard HTTP request to the static endpoint, still deploys the vulnerable serveStatic method carries a remote information disclosure risk.

Generated by OpenCVE AI on September 15, 2026 at 17:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade node-restify to a version newer than 12.0.0 that includes the fixed serveStatic implementation.
  • Limit the static directory served by restricting the path to a dedicated public subdirectory, ensuring that sensitive files are not exposed.
  • Add input validation to reject request paths containing ".." or other traversal patterns before they reach serveStatic, preventing unsafe path resolution.

Generated by OpenCVE AI on September 15, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Restify restify
Vendors & Products Restify restify

Sun, 13 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title restify node-restify static.js serveStatic path traversal
First Time appeared Restify
Restify node-restify
Weaknesses CWE-22
CPEs cpe:2.3:a:restify:node-restify:*:*:*:*:*:*:*:*
Vendors & Products Restify
Restify node-restify
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Restify Node-restify Restify
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T16:18:52.343Z

Reserved: 2026-09-12T08:15:25.203Z

Link: CVE-2026-90494

cve-icon Vulnrichment

Updated: 2026-09-21T16:18:49.037Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T04:17:15.373

Modified: 2026-09-21T17:19:14.883

Link: CVE-2026-90494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')