
CVE-2026-53571 `server.fs.deny` bypass on Windows alternate paths PoC.
CVE-2026-53571 server.fs.deny bypass on Windows alternate paths PoC.
The contents of files that are specified by server.fs.deny can be returned to the browser on Windows.
mkdir CVE-2026-53571
cd CVE-2026-53571
npm init -y
npm install [email protected]
Verification:
python3 ./poc.py