PT-2026-60564 · Whistle · Whistle
CVE-2026-55629
·
Published
2026-07-16
·
Updated
2026-08-25
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Whistle versions prior to 2.10.3
Description
An issue exists in the way the software handles the 'GET /cgi-bin/temp/get' endpoint. The system reads the
filename variable from the query string and only joins it to the temporary files path if it matches a specific pattern; otherwise, it passes the user-supplied filename directly to the getFile() function. This allows a remote attacker to read arbitrary files on the system, such as /etc/passwd.Recommendations
Update to version 2.10.3.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Whistle