CVE-2026-55629
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
16/07/2026
Last modified:
17/07/2026
Description
Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise passing the user-supplied filename directly to getFile, allowing a remote attacker to read arbitrary files such as /etc/passwd. This issue is reported as fixed in version 2.10.3.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



