Junglewise Threat Intelligence

CVE-2026-54650: bablilayoub openhole path traversal in openhole-server

CVE-2026-54650 · Severity: high · CVSS 8.6 · Published 2026-07-28

Vendors: Go.

Executive brief

openhole is a tool used to expose local development servers to the internet. A security flaw in the way it handles web addresses allows attackers to bypass security restrictions and access files or folders on the local machine that were never intended to be public. This could lead to the theft of sensitive data, such as configuration files or system passwords, from the computer running the tool.

Technical details

A path traversal vulnerability exists in openhole-server (internal/server/public_proxy.go) due to the use of r.URL.Path instead of r.URL.EscapedPath() when forwarding requests to tunneled clients. Because r.URL.Path is automatically decoded by Go's net/http package, percent-encoded dot segments (%2e) and separators (%2f) are converted to '../' and '/' before reaching the backend service. This allows an unauthenticated remote attacker to bypass Go's default ServeMux protections and access sensitive files on the local service that do not perform their own path canonicalization. The issue is fixed in version 0.1.2 by ensuring the original request target is preserved.

Affected products

  • bablilayoub openhole <= 0.1.1

Timeline

  • 2026-06-08: patched: Fix committed and version 0.1.2 released
  • 2026-07-28: disclosed: CVE-2026-54650 published

References