CVE-2025-66415: fastify-reply-from affected by bypass of reply forwarding
By crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66415 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →