MEDIUM
restify
CVE published 2026-09-13
CVE-2026-90494
A path traversal vulnerability was found in restify node-restify up to 12.0.0, affecting the serveStatic function in /lib/plugins/static.js. The attack can be initiated remotely. This vulnerability allows remote attackers to manipulate the path, potentially leading to unauthorized access or data exposure. Defenders should assess exposure and prioritize remediation for systems using restify node-restify up [truncated]