CVE-2026-90494: Restify Node-Restify

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Restify Node-Restify: version 12.0 only

Published 2026-09-13. Last modified 2026-09-21.