Executive brief
Allure Report is a tool used to generate and view interactive test reports, often used in software development and CI/CD pipelines. A security flaw in its built-in web server allows an attacker to bypass directory restrictions and read any file on the host system that the Allure process can access. This could lead to the theft of sensitive information such as SSH keys, environment variables, and system credentials.
Technical details
A path traversal vulnerability exists in the 'allure serve' and 'allure open' commands within the io.qameta.allure:allure-commandline package. The root cause is in the Commands.setUpServer() method, which resolves request URI paths directly against the report directory without path normalization or validation. An attacker can use '../' sequences or percent-encoded equivalents (%2e%2e) to access files outside the intended directory. While the server binds to localhost by default, it is often configured to bind to all interfaces in containerized or CI/CD environments, making it reachable over the network. The vulnerability is patched in version 2.39.0.
Affected products
- io.qameta.allure allure-commandline <= 2.38.1
Timeline
- 2026-06-16: disclosed
- 2026-06-19: advisory
- 2026-06-19: patched