CVE-2026-55629
Last modified
CVE-2026-55629 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise passing the user-supplied filename directly to getFile, allowing a remote attacker to read arbitrary files such as /etc/passwd. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise passing the user-supplied filename directly to getFile, allowing a remote attacker to read arbitrary files such as /etc/passwd. This issue is reported as fixed in version 2.10.3.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| avwo | whistle | < 2.10.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55629?
How severe is CVE-2026-55629?
How do I fix CVE-2026-55629?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55622Incus is a system container and virtual machine manager. Pri…7.7
- CVE-2026-55623Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2026-55624MintyItanium Lost-Auction is an auction plugin for Minecraft…5.3
- CVE-2026-55625GoCD is a continuous deliver server. From 16.1.0 until 26.1.…4.9
- CVE-2026-55626xrdp is an open source RDP server. In versions 0.10.6 and pr…7.3
- CVE-2026-55628ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-5563A security flaw has been discovered in AutohomeCorp frostmou…6.3
- CVE-2026-55630Kiwi TCMS is an open source test management system. Prior to…0
- CVE-2026-55631DataEase is an open source data visualization and analysis t…7.2
- CVE-2026-55632GoCD is a continuous deliver server. From 20.2.0 until 26.1.…4.3
- CVE-2026-55633DataEase is an open source data visualization and analysis t…8.7
- CVE-2026-55634Pimcore is an Open Source Data & Experience Management Platf…9.9
Are you affected by CVE-2026-55629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
