A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-7120

CVE-2026-7120 updated by NVD

Published
2026-07-24
Modified
2026-07-30
EPSS percentile
14%
Sources
github-advisory, nvd

Summary

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@fastify/static10.1.2

Remediation: Upgrade to 10.1.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.