Threat Advisory

Webpack Dev Middleware Path Traversal Vulnerability Allows Arbitrary File Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in webpack-dev-middleware that could allow an attacker to read files outside the output root via a path traversal attack. The impact is considered high, and applications serving webpack-dev-middleware with a publicPath that does not end in a slash are affected. The vulnerable version range for webpack-dev-middleware is >= 8.0.0, < 8.3.0 and < 7.4.5.

CVE-2026-76844 (CVSS 7.4 — Severity): This vulnerability allows an unauthenticated request to read files outside the output root via a path traversal attack when the configured publicPath has no trailing slash.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in webpack-dev-middleware that could allow an attacker to read files outside the output root via a path traversal attack. The impact is considered high, and applications serving webpack-dev-middleware with a publicPath that does not end in a slash are affected. The vulnerable version range for webpack-dev-middleware is >= 8.0.0, < 8.3.0 and < 7.4.5.

CVE-2026-76844 (CVSS 7.4 — Severity): This vulnerability allows an unauthenticated request to read files outside the output root via a path traversal attack when the configured publicPath has no trailing slash.[emaillocker id="1283"]

CVE-2024-29180: This earlier path traversal in webpack-dev-middleware is bypassed by this issue.

These vulnerabilities collectively present a high risk of arbitrary file access for applications serving webpack-dev-middleware with a vulnerable configuration.

RECOMMENDATION:

We recommend you to update webpack-dev-middleware to version 8.3.0 or 7.4.6 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu