High severityNVD Advisory· Published Jul 28, 2026· Updated Jul 29, 2026
openhole-server vulnerable to path traversal via URL-decoded request path
CVE-2026-54650
Description
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/bablilayoub/openholeGo | < 0.1.2 | 0.1.2 |
Affected products
1- Range: <=0.1.1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-fh2f-xfxc-q9ccghsaADVISORY
- github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3ghsax_refsource_MISCWEB
- github.com/bablilayoub/openhole/releases/tag/v0.1.2ghsax_refsource_MISCWEB
- github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9ccghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.