PatchSiren cyber security CVE debrief
CVE-2026-90494 restify CVE debrief
A path traversal vulnerability was found in restify node-restify up to 12.0.0, affecting the serveStatic function in /lib/plugins/static.js. The attack can be initiated remotely. This vulnerability allows remote attackers to manipulate the path, potentially leading to unauthorized access or data exposure. Defenders should assess exposure and prioritize remediation for systems using restify node-restify up to 12.0.0. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendor
- restify
- Product
- node-restify
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-13
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-13
- Advisory updated
- 2026-09-21
Who should care
Defenders and administrators of systems using restify node-restify up to 12.0.0 should assess exposure and prioritize remediation. This includes reviewing compensating controls for exposed systems, checking relevant monitoring, detection, and logs for exposed assets, and tracking exceptions and retesting remediated assets. The vulnerability allows remote attackers to manipulate the path, potentially leading to unauthorized access or data exposure.
Why it matters
CVE-2026-90494 is a path traversal vulnerability in restify node-restify up to 12.0.0. Defenders should assess exposure, prioritize remediation, and verify vendor response.
- Path traversal allows remote attackers to access unauthorized files
- Potential for data exposure or manipulation
- Requires verification of affected versions and vendor remediation plans
- Defenders should prioritize inventory checks and monitoring for suspicious activity
Technical summary
The serveStatic function in /lib/plugins/static.js of restify node-restify up to 12.0.0 is vulnerable to path traversal. This allows remote attackers to manipulate the path, potentially leading to unauthorized access or data exposure. The vulnerability has been confirmed in restify node-restify up to 12.0.0, and defenders should assess exposure and prioritize remediation. The attack can be initiated remotely, and defenders should verify affected versions and vendor remediation plans. The CVE record and NVD entry provide details on the vulnerability.
Defensive priority
Assess exposure and prioritize remediation for systems using restify node-restify up to 12.0.0.
Recommended defensive actions
- Assess systems using restify node-restify up to 12.0.0 for exposure
- Prioritize remediation for affected systems
- Verify vendor response and remediation plans
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the vendor did not respond to early disclosure. The vulnerability has been confirmed in restify node-restify up to 12.0.0, and defenders should verify affected versions and vendor remediation plans. The serveStatic function in /lib/plugins/static.js is specifically affected, allowing remote attackers to manipulate the path.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90494 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90494
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90494 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90494
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-90494
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/892870
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/403082
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/403082/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.