A AegiFlow
HIGHCVSS 8.6EPSS 0.4%

CVE-2026-54650

CVE-2026-54650 updated by NVD

Published
2026-07-28
Modified
2026-07-31
EPSS percentile
29%
Sources
github-advisory, nvd

Summary

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/bablilayoub/openhole0.1.2

Remediation: Upgrade to 0.1.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.