VYPR
Medium severity5.3GHSA Advisory· Published Jul 17, 2026· Updated Jul 23, 2026

CVE-2026-48049

CVE-2026-48049

Description

@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured with path in the directory or file handlers or relativeTo for h.file(), with confinement enforced by the confine option, but the confinement check compared the resolved absolute path against the confine directory using a raw string-prefix test, so a sibling directory such as /app/static-secret next to /app/static was incorrectly accepted and could allow an unauthenticated remote attacker to read files via /..%2fstatic-secret/secret.txt. This issue is fixed in version 7.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@hapi/inertnpm
>= 4.0.0, < 7.1.17.1.1

Affected products

21

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.