A high-severity path traversal vulnerability tracked as CVE-2026-55629 was disclosed in Whistle, the HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. The flaw affects versions prior to 2.10.3 and stems from the /cgi-bin/temp/get handler in lib/service/service.js, which passed a user-controlled filename directly to file retrieval logic. An unauthenticated remote attacker could exploit the issue without user interaction to read arbitrary files on the host, including sensitive system files such as /etc/passwd.
The issue received a CVSS 4.0 score of 8.7 and was addressed in Whistle 2.10.3, with public references pointing to the project release, a fixing commit, and a GitHub security advisory. Subsequent project changes also show broader hardening in Whistle's service and temporary-file handling, including centralized temp-file utilities and a UID-based authorization check for service endpoints, alongside other fixes to proxy authorization, parsing, and plugin-related logic.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A high-severity path traversal vulnerability affecting Whistle versions prior to 2.10.3 was fixed in release 2.10.3. The flaw in the /cgi-bin/temp/get handler could let remote attackers read arbitrary files such as /etc/passwd without privileges or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.