Executive brief
OpenBullet2, an automation suite used for web testing, contains a security flaw in its wordlist management system. An authenticated user can bypass folder restrictions to read, write, or delete any file on the underlying server. Because the application typically runs with high system privileges, an attacker can take complete control of the server, potentially leading to data theft or a total service outage.
Technical details
A path traversal vulnerability (CWE-22) exists in the wordlist endpoint of OpenBullet2 through version 0.3.2. The vulnerability stems from the upload handler and wordlist functions failing to sanitize absolute paths provided by users. An authenticated attacker can exploit this via the network to perform arbitrary file operations. By chaining file write and delete primitives, an attacker can manipulate critical system files (such as /etc/passwd). Since the application runs as root by default, this leads to full system compromise and remote code execution.
Affected products
- OpenBullet2 OpenBullet2 through 0.3.2
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory: NVD publication date