MEDIUM
CVE-2026-90494
CVSS
5.3
Description
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
0.55%
Probability of exploitation in next 30 days
44.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.