Executive brief
Algernon is a web server used by developers to build and test websites. In versions prior to 1.17.7, a background service used for live-updating pages was configured to listen on all network interfaces by default on Linux and macOS. This allows other users on the same local network (such as a public WiFi or office LAN) to see which files the developer is editing without any authorization, potentially exposing sensitive project filenames or environment variables.
Technical details
Algernon web server (prior to 1.17.7) contains an insecure default initialization vulnerability where the SSE event server binds to 0.0.0.0:5553 on Linux and macOS. This occurs because the platform-dependent host default in 'engine/flags.go' was set to an empty string for non-Windows platforms, which 'utils.JoinHostPort' resolves to a wildcard bind. An attacker on the same adjacent network (LAN) can connect to the SSE endpoint without authentication to monitor file-change streams, revealing filenames and edit timings. Windows installations were unaffected as they defaulted to 'localhost'. The issue is resolved in version 1.17.7 by ensuring the SSE server defaults to the loopback interface across all platforms.
Affected products
- xyproto Algernon < 1.17.7
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-05-26: disclosed: CVE published to NVD