CVE-2026-59179 is a CWE-22 path-traversal vulnerability affecting @openhop/server 0.3.5 and OpenHop CLI 0.3.6. The server uses an unauthenticated flow identifier supplied through HTTP routing to construct YAML flow-storage filenames with Node.js path joining, without restricting the identifier to valid flow-name characters. URL-encoded traversal sequences are decoded by the routing layer before reaching application code; subsequent path normalization can escape the configured flow-storage directory. The affected flow retrieval operation reads the resolved YAML file, while the flow deletion operation removes it.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity unauthenticated path-traversal vulnerability in @openhop/server Flow ID file operations. Percent-encoded traversal sequences in GET and DELETE flow routes are decoded and passed to path.join(), enabling reading and deletion of YAML files outside the intended flow-store directory. CORS configured to allow all origins enables browser-based exploitation of local instances, while default Docker binding to 0.0.0.0 exposes server deployments remotely.
A high-severity CWE-22 path-traversal vulnerability in OpenHop flow-file operations. Unauthenticated attackers can escape the configured flow storage directory to read accessible YAML files and delete accessible YAML files. Broad CORS configuration enables browser-based attacks against local instances, while Docker deployments binding to 0.0.0.0 can be directly reachable over the network.
A high-severity vulnerability affecting @openhop/server, classified under CWE-22 (path traversal). Its CVSS v3 base score is 8.3, with network access, no required privileges, and required user interaction. The advisory reports high integrity and availability impacts. A fix is available in version 0.3.6 or later; the patch and vulnerability were published on September 9, 2026.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.