THREAT OPS › Threat News › [GHSA] GHSA-3vfr-4gwf-qxfp (high) — Whistle vulnerable to path traversal
[GHSA] GHSA-3vfr-4gwf-qxfp (high) — Whistle vulnerable to path traversal
GHSA-3vfr-4gwf-qxfp Severity: high CVE: CVE-2026-55629
Whistle vulnerable to path traversal
This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.
**Vulnerability detail**:
In service.js, inside `app.get('/cgi-bin/temp/get', ...): var filename = req.query.filename; if (TEMP_FI
Indicators of compromise
- CVE-2026-55629cve
- http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/passwdurl
- http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/hostsurl
- lanyundev.comdomain
- www.proxifier.comdomain
- proxifier.comdomain
- tlocalhost.sangfor.com.cndomain
Original source: https://github.com/advisories/GHSA-3vfr-4gwf-qxfp