CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation
Vulnerability ID: CVE-2026-76844
CVSS Score: 7.4
Published: 2026-09-29
CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.
TL;DR
webpack-dev-middleware suffers from a path traversal flaw when publicPath lacks a trailing slash and physical files are served, allowing attackers to read files one directory above the output root via crafted HTTP requests like GET /assets../.env.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22 (Path Traversal)
- Attack Vector: Network (AV:N)
- CVSS v3.1: 7.4 (High)
- EPSS Score: 0.00483
- Impact: Confidentiality (High)
- Exploit Status: Proof-of-Concept (PoC)
- KEV Status: Not Listed
Affected Systems
- webpack-dev-middleware versions 5.3.4, 6.1.2-6.1.3, 7.1.0-7.4.5, 8.0.0-8.1.1 configured with writeToDisk or custom physical outputFileSystem
-
webpack-dev-middleware: >= 5.3.4, <= 8.1.1 (Fixed in:
7.4.6, 8.3.0)
Code Analysis
Commit: 13344e7
Enforce boundary checks on resolved filenames in getFilenameFromUrl to prevent path traversal when publicPath lacks a trailing slash
Commit: cefccba
Resolve traversal flaws using absolute containment checks via path.relative
Exploit Details
- GitHub Advisory / Patch Tests: Integration tests illustrating path resolution exploit vector using /static../ test suite cases
Mitigation Strategies
- Upgrade webpack-dev-middleware to a non-vulnerable version (7.4.6+ or 8.3.0+).
- Append a trailing slash to the configured publicPath parameter to ensure precise prefix matching.
Remediation Steps:
- Identify the version of webpack-dev-middleware installed in your package-lock.json or yarn.lock file.
- Update your dependencies using 'npm install webpack-dev-middleware@7.4.6' or 'npm update webpack-dev-middleware'.
- Inspect the webpack configuration file (webpack.config.js) and verify that 'output.publicPath' terminates with a trailing slash (e.g., '/static/' instead of '/static').
- Restart your development server to load the updated middleware logic.
References
- GitHub Security Advisory GHSA-wr3j-pwj9-hqq6
- webpack-dev-middleware Middleware Source File
- VulnCheck Advisory for webpack-dev-middleware
- Fix Commit 1 (v8.x/v7.x)
- Fix Commit 2
Read the full report for CVE-2026-76844 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)