Executive brief
@fastify/swagger-ui is a Fastify plugin that provides API documentation via Swagger UI. When using the default configuration without setting the baseDir option, the plugin exposes all files in its module directory via HTTP routes, allowing unauthorized access to sensitive files that should not be publicly accessible.
Technical details
The vulnerability is an information disclosure (CWE-200) in @fastify/swagger-ui versions 2.0.0 through 2.0.x. When the baseDir option is not explicitly configured, the plugin's default behavior allows unauthenticated, network-based access to enumerate and download all files within the module's directory structure via HTTP routes. The attack requires no privileges, user interaction, or special complexity—any network-connected attacker can directly request files through the web interface. The issue affects confidentiality but not integrity or availability. The fix is available in version 2.1.0; users can also mitigate by explicitly setting the baseDir option.
Affected products
- Fastify @fastify/swagger-ui 2.0.0 to 2.0.x
Timeline
- 2024-01-15: disclosed
- 2024-01-16: patched: v2.1.0 released