CVE-2026-6410Disclosure(fastify / fastify-static)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch fastify fastify-static systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a containment check. A remote unauthenticated attacker can obtain directory listings for arbitrary directories accessible to the Node.js process, disclosing directory and file names. File contents are not disclosed. Upgrade to @fastify/static 9.1.1 to fix this issue. As a workaround, disable directory listing by removing the list option from the plugin configuration.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify-static

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-17)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fastify-static

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-16: 2Mentions · 2026-04-17: 3Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 204-1604-17
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure1Patch1
2026-04-173
Disclosure2General1
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6410 @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directorie… https://www.cve.org/CVERecord?id=CVE-2026-6410 ----- Traducción: CVE-2026-6410: la… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6410 as a path‑traversal flaw in fastify/static, providing technical details but no evidence of exploitation, PoC, or patches.

    0000023
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6410 @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directorie… https://www.cve.org/CVERecord?id=CVE-2026-6410

    Post summary

    The article details a path traversal flaw in @fastify/static, noting affected versions and the specific condition that triggers it, but offers no PoC, exploit tool, or patch information.

    0000096
    57.2K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Nodejs, Path Traversal, #CVE-2026-6410 (Medium) https://dailycve.com/nodejs-path-traversal-cve-2026-6410-medium/

    Post summary

    The snippet merely announces the existence of CVE-2026-6410 with a medium severity rating and provides a link, without further technical details or actionable information.

    0000029
    181 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6410 Path Traversal in @fastify/static 8.0.0 Through 9.1.0 Directory Listing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6410

    Post summary

    A Path Traversal vulnerability (CVE‑2026‑6410) affecting @fastify/static 8.0.0‑9.1.0 is reported; no evidence of PoC, exploit, active attacks, or patch is provided.

    0000044
    4.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in @fastify/static@9.1.1 just released! Patches CVE-2026-6410 — path traversal in directory listing https://github.com/fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h

    Post summary

    The post announces the release of a security fix for CVE-2026-6410, a path traversal vulnerability in fastify/static, and directs readers to the GitHub advisory for details.

    0000085
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-static---

Explore more