A vulnerability was found in bablilayoub openhole up to 0.1.1 and classified as critical. The affected element is the function r.URL.Path of the file internal/server/public_proxy.go of the component Public Proxy. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-54650. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.