OVERVIEW CVE-2026-6410 is a path traversal vulnerability affecting @fastify/static versions 8.0.0 through 9.1.0. When directory listing is enabled via the list option, the dirList.path() function fails to properly validate directory boundaries, allowing attackers to enumerate arbitrary directories accessible to the Node.js process. While directory and file names are disclosed, file contents remain protected. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.3 (MEDIUM) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, indicating minimal technical barriers to exploitation. The impact is limited to confidentiality, specifically the disclosure of directory structures and file naming conventions that could inform further attacks. No integrity or availability impact is present. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation. The EPSS score of 0.00023 indicates minimal real-world exploitation probability. Community attention appears minimal given the low risk categorization and inactive hot list status. Organizations should prioritize patching through upgrade to version 9.1.1 or implement the recommended workaround of disabling directory listing functionality.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 9.1.1CPE matchmatch criteria | cpe:2.3:a:fastify:fastify-static:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.