Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6410

21
FAUCET Score

OVERVIEW CVE-2026-6410 is a path traversal vulnerability affecting @fastify/static versions 8.0.0 through 9.1.0. When directory listing is enabled via the list option, the dirList.path() function fails to properly validate directory boundaries, allowing attackers to enumerate arbitrary directories accessible to the Node.js process. While directory and file names are disclosed, file contents remain protected. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.3 (MEDIUM) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, indicating minimal technical barriers to exploitation. The impact is limited to confidentiality, specifically the disclosure of directory structures and file naming conventions that could inform further attacks. No integrity or availability impact is present. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation. The EPSS score of 0.00023 indicates minimal real-world exploitation probability. Community attention appears minimal given the low risk categorization and inactive hot list status. Organizations should prioritize patching through upgrade to version 9.1.1 or implement the recommended workaround of disabling directory listing functionality.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 9.1.1CPE matchmatch criteria
cpe:2.3:a:fastify:fastify-static:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 26th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: @fastify/staticFixed in: 9.1.1

Vendor Advisories (1)

npmGHSA-pr96-94w5-mx2hmedium

@fastify/static vulnerable to path traversal in directory listing

Apr 16, 2026

References

cna.openjsf.org / security-advisories.html
Third Party Advisory
github.com / fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h
MitigationVendor Advisory