{"id":"GHSA-fh2f-xfxc-q9cc","summary":"openhole-server vulnerable to path traversal via URL-decoded request path","details":"## Summary\n\nopenhole-server forwarded the URL-decoded request path (`r.URL.Path`) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (`%2e`) and separators (`%2f`) were decoded to `../` and `/` before reaching the local service.\n\nGo's ServeMux rejects literal `../` paths, but percent-encoded traversal sequences bypassed this and were delivered to backends as working path traversal.\n\n## Impact\n\nAn unauthenticated remote attacker could read files outside the published web root on tunneled local services that resolve paths without canonicalization.\n\nExample:\n- `/%2e%2e/secret.txt` → file outside web root\n- `/%2e%2e/%2e%2e/etc/passwd` → sensitive files\n\nEncoded slashes (`/a%2fb`) could also bypass path-based access controls.\n\n## Fix\n\nv0.1.2 forwards `r.URL.EscapedPath()` on the server and preserves the request-target on the CLI client.\n\nUsers should upgrade both openhole-server and the openhole CLI to v0.1.2 or later.","aliases":["CVE-2026-54650","GO-2026-6135"],"modified":"2026-08-18T15:10:40.020067994Z","published":"2026-07-28T22:20:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-28T22:20:51Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc"},{"type":"WEB","url":"https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3"},{"type":"PACKAGE","url":"https://github.com/bablilayoub/openhole"},{"type":"WEB","url":"https://github.com/bablilayoub/openhole/releases/tag/v0.1.2"}],"affected":[{"package":{"name":"github.com/bablilayoub/openhole","ecosystem":"Go","purl":"pkg:golang/github.com/bablilayoub/openhole"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fh2f-xfxc-q9cc/GHSA-fh2f-xfxc-q9cc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}