VYPR

Openhop

by Naorsabag

CVEs (1)

  • CVE-2026-59179higSep 9, 2026
    risk 0.38cvss epss

    ## Path Traversal in Flow ID File Operations ### Summary `@openhop/server` passes unsanitized HTTP route parameters directly to `path.join()` when constructing filesystem paths for flow YAML files. An unauthenticated attacker who can reach the server can read arbitrary `.yaml`…