CVE-2026-90494 | restify node-restify up to 12.0.0 /lib/plugins/static.js serveStatic path traversal
A vulnerability was found in restify node-restify up to 12.0.0. It has been rated as problematic. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-90494. The attack can be initiated remotely. There is not any exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More