VYPR

Whistle

by Avwo

npm: whistle

Source repositories

CVEs (2)

  • CVE-2024-55500HigDec 10, 2024
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

  • CVE-2026-55629HigJul 16, 2026
    risk 0.00cvss epss 0.00

    Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise passing the…