THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2mf3-mr2r-r4vf (high) — @rhinostone/swig: arbitrary local file read via include/extends path traversal

[GHSA] GHSA-2mf3-mr2r-r4vf (high) — @rhinostone/swig: arbitrary local file read via include/extends path traversal

highgithub_advisoriesPublished 2026-08-18

GHSA-2mf3-mr2r-r4vf Severity: high CVE: None

@rhinostone/swig: arbitrary local file read via include/extends path traversal

### Overview

`@rhinostone/swig` is a maintained fork of the abandoned `swig` template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The `{% include %}`, `{% extends %}`, and `{% import %}` tags resolve

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2mf3-mr2r-r4vf