VDB
KO
MEDIUM 5.3

GHSA-8pvw-jcv7-9cmj

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

Quick fix

GHSA-8pvw-jcv7-9cmj — @fastify/static: upgrade to the fixed version with the command below.

npm install @fastify/static@10.1.2

Details

### Impact

`@fastify/static` evaluates the `allowedPath` callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as `//file`, `/./file`, or `/public/../private/file` bypass `allowedPath` filtering while resolving to the intended file on disk.

Applications that use `allowedPath` as a security boundary to restrict access to specific static files or path subtrees may unintentionally expose files that were intended to be denied.

### Patches

Upgrade to `@fastify/static` >= 10.1.2.

### Workarounds

None. Upgrade to the patched version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @fastify/static
Introduced in: 0 Fixed in: 10.1.2
Fix npm install @fastify/static@10.1.2

References