PT-2026-94186 · Npm · Fastify-Static
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
@fastify/static versions prior to 10.1.4
Description
On case-insensitive filesystems, such as Windows or default macOS volumes, a route guard or
allowedPath restriction can be bypassed by altering the letter case of a path segment. This occurs because the route matcher is case-sensitive while the filesystem is not; a request with a modified case does not match the guarded route and is passed to the static handler, which the filesystem then resolves to the protected file. Consequently, unauthenticated requests can read files intended to be protected. This issue is not a directory traversal as it does not allow access to files outside the configured root, and it does not affect case-sensitive filesystems.Recommendations
Update to version 10.1.4.
Serve static files from a case-sensitive filesystem.
Ensure route guards and
allowedPath rules account for every letter-case variant of the protected paths.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fastify-Static