6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Basic Information
ID
CVE-2025-66415
Source
GitHub_M
Published
Dec 1, 2025 at 22:39
Affected Product
Vendor
fastify
Product
fastify-reply-from
Version
< 12.5.0
Affected Versions
fastify fastify-reply-from < 12.5.0