DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-76844: CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation

CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation

Vulnerability ID: CVE-2026-76844
CVSS Score: 7.4
Published: 2026-09-29

CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.

TL;DR

webpack-dev-middleware suffers from a path traversal flaw when publicPath lacks a trailing slash and physical files are served, allowing attackers to read files one directory above the output root via crafted HTTP requests like GET /assets../.env.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22 (Path Traversal)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 7.4 (High)
  • EPSS Score: 0.00483
  • Impact: Confidentiality (High)
  • Exploit Status: Proof-of-Concept (PoC)
  • KEV Status: Not Listed

Affected Systems

  • webpack-dev-middleware versions 5.3.4, 6.1.2-6.1.3, 7.1.0-7.4.5, 8.0.0-8.1.1 configured with writeToDisk or custom physical outputFileSystem
  • webpack-dev-middleware: >= 5.3.4, <= 8.1.1 (Fixed in: 7.4.6, 8.3.0)

Code Analysis

Commit: 13344e7

Enforce boundary checks on resolved filenames in getFilenameFromUrl to prevent path traversal when publicPath lacks a trailing slash

Commit: cefccba

Resolve traversal flaws using absolute containment checks via path.relative

Exploit Details

Mitigation Strategies

  • Upgrade webpack-dev-middleware to a non-vulnerable version (7.4.6+ or 8.3.0+).
  • Append a trailing slash to the configured publicPath parameter to ensure precise prefix matching.

Remediation Steps:

  1. Identify the version of webpack-dev-middleware installed in your package-lock.json or yarn.lock file.
  2. Update your dependencies using 'npm install webpack-dev-middleware@7.4.6' or 'npm update webpack-dev-middleware'.
  3. Inspect the webpack configuration file (webpack.config.js) and verify that 'output.publicPath' terminates with a trailing slash (e.g., '/static/' instead of '/static').
  4. Restart your development server to load the updated middleware logic.

References


Read the full report for CVE-2026-76844 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)