Product
The Whistle npm package contains a path traversal vulnerability (CVE-2026-55629) in the /cgi-bin/temp/get endpoint, allowing unauthorized attackers to read arbitrary files from the filesystem.