VDB
KO
HIGH 7.5

GHSA-83w8-p2f5-377r

@fastify/static vulnerable to route guard bypass via path traversal

Quick fix

GHSA-83w8-p2f5-377r — @fastify/static: upgrade to the fixed version with the command below.

npm install @fastify/static@10.1.1

Details

### Impact

`@fastify/static` is vulnerable to a bypass of route-based middleware and guards via non-leading `..` and `%2E%2E` path segments. `find-my-way` does not normalize `..` when matching routes, so a request such as `/foo/../deep/secret.txt` matches the static plugin's catch-all instead of the guarded `/deep/*`. The `getPathnameForSend` helper introduced by the fix for [GHSA-x428-ghpx-8j92](https://github.com/fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92) only guards against the `%2F` variant; `..` and `%2E%2E` survive the `decodeURI` + `encodeURI` round-trip and are then collapsed away by `@fastify/send`'s `path.normalize` before its own traversal guard runs.

Applications that rely on route-based middleware or guards to protect files served by `@fastify/static` can be bypassed with non-leading dot-dot path segments.

### Patches

Upgrade to `@fastify/static` 10.1.1.

### Workarounds

Do not use route-based middlewares or guards to protect files served by `@fastify/static`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @fastify/static
Introduced in: 0 Fixed in: 10.1.1
Fix npm install @fastify/static@10.1.1

References