CVE-2026-76844: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in webpack webpack-dev-middleware
Description
CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware. It arises from improper pathname validation when the configured publicPath lacks a trailing slash, allowing crafted requests to bypass traversal guards and access files outside the intended directory. This vulnerability affects versions starting from 5.3.4, 6.1.2, 7.1.0, and later up to 8.1.1. The issue is a partial regression of a previous vulnerability (CVE-2024-29180) and requires the middleware to be backed by a physical filesystem to be exploitable. No official patch or remediation guidance is currently provided.
CVSS v4.0
Score 8.3high
Affected software
webpack
webpack-dev-middleware
pkg:npm/webpack-dev-middlewareRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in webpack-dev-middleware occurs because the pathname validation logic only matches '..' as a whole path segment and slices the pathname at a fixed offset. When publicPath is configured without a trailing slash, requests like GET /assets../.env can bypass the traversal guard since '..' is embedded inside a segment and not detected. The slicing then extracts '../.env', which path.join resolves to a directory above the intended outputPath. Exploitation requires the middleware to use a physical filesystem (writeToDisk=true or custom outputFileSystem) since the default in-memory filesystem does not hold arbitrary files. The traversal depth is limited to one directory due to URL parsing collapsing dot-dot segments. This vulnerability is present in all releases from 5.3.4, 6.1.2, 7.1.0 onward, including 8.x versions, and represents an incomplete fix of CVE-2024-29180.
Potential Impact
An attacker can craft a specially formed request to access files outside the intended directory served by webpack-dev-middleware, potentially exposing sensitive files on the server filesystem. This can lead to information disclosure if the middleware is configured to write to disk or uses a custom output filesystem that reflects the physical filesystem. The vulnerability does not require privileges or user interaction beyond sending a crafted HTTP request. The traversal depth is limited to one directory above the output path.
Mitigation Recommendations
No official patch or remediation level is currently documented. Users should verify their publicPath configuration to ensure it includes a trailing slash to prevent bypass of the traversal guard. Additionally, avoid enabling writeToDisk or using a custom outputFileSystem that exposes the physical filesystem unless necessary. Monitor vendor advisories for updates or patches addressing this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-19T20:34:19.724Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8c45b3acd9273b49946349
Added to database: 08/24/2026, 13:22:59 UTC
Last enriched: 09/10/2026, 11:07:23 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.