ADVISORYHIGH7d ago · Sep 9, 2026
@openhop/server: Path Traversal in Flow ID File Operations

Unauthenticated attackers who can reach @openhop/server can exploit its flow ID file operations.
Path Traversal in Flow ID File Operations Summary @openhop/server passes unsanitized HTTP route parameters directly to path.join() when constructing filesystem paths for flow YAML files. An unauthenticated attacker who can reach the server can read…
Read it at @openhop/server