A high-severity path traversal flaw tracked as CVE-2026-54650 was disclosed in the openhole project, affecting openhole-server and the CLI client in versions 0.1.1 and earlier. The bug stemmed from improper handling of request paths in the proxy chain: the server forwarded r.URL.Path instead of preserving the original escaped request target, while client-side proxy code constructed backend URLs in a way that let attacker-controlled paths pass through to local services. As a result, percent-encoded traversal sequences such as %2e and %2f could be interpreted as ../ and /, enabling remote access to unintended files.
The vulnerability is classified as CWE-22 with a CVSS 3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N, indicating high confidentiality impact without requiring authentication or user interaction. Reported attack paths included requests such as /../../etc/passwd and encoded equivalents routed through the proxy to tunneled local backends. The issue was fixed in openhole version 0.1.2 by switching the server to r.URL.EscapedPath() and updating the client to build requests with a structured url.URL object that preserves RawPath and safely decodes Path.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
The path traversal vulnerability affecting openhole-server and the openhole CLI client was remediated in openhole version 0.1.2. The fix changed server path handling to use r.URL.EscapedPath() and updated the client to construct backend requests safely with a structured url.URL object.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.