A vulnerability was found in avwo Whistle up to 2.10.2. It has been rated as problematic. Affected is the function getFile of the file lib/service/service.js of the component Temporary File Handler. The manipulation of the argument filename leads to insecure temporary file.

This vulnerability is documented as CVE-2026-55629. The attack can be initiated remotely. There is not any exploit available.