Multiple security vulnerabilities have been identified in webpack-dev-middleware that could allow an attacker to read files outside the output root via a path traversal attack. The impact is considered high, and applications serving webpack-dev-middleware with a publicPath that does not end in a slash are affected. The vulnerable version range for webpack-dev-middleware is >= 8.0.0, < 8.3.0 and < 7.4.5.
CVE-2026-76844 (CVSS 7.4 — Severity): This vulnerability allows an unauthenticated request to read files outside the output root via a path traversal attack when the configured publicPath has no trailing slash.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in webpack-dev-middleware that could allow an attacker to read files outside the output root via a path traversal attack. The impact is considered high, and applications serving webpack-dev-middleware with a publicPath that does not end in a slash are affected. The vulnerable version range for webpack-dev-middleware is >= 8.0.0, < 8.3.0 and < 7.4.5.
CVE-2026-76844 (CVSS 7.4 — Severity): This vulnerability allows an unauthenticated request to read files outside the output root via a path traversal attack when the configured publicPath has no trailing slash.[emaillocker id="1283"]
CVE-2024-29180: This earlier path traversal in webpack-dev-middleware is bypassed by this issue.
These vulnerabilities collectively present a high risk of arbitrary file access for applications serving webpack-dev-middleware with a vulnerable configuration.
We recommend you to update webpack-dev-middleware to version 8.3.0 or 7.4.6 depending on your installed branch.
The following reports contain further technical details:
[/emaillocker]