Impact
Allure 2’s HTTP server, launched by the allure serve and allure open commands, handles request paths by decoding the URI and resolving them in the report directory. In versions before 2.39.0, the server does not normalize the resolved path or verify that it stays within the report directory. An unauthenticated adversary able to reach the server can include parent-directory segments, including percent-encoded ones, in the request path, causing the server to serve any regular file that the Allure process can read. The server defaults to binding to localhost, but the --host option can expose it to other systems; local users, adjacent containers, or browser‑origin attacks may therefore reach the listener. As a result, the flaw can disclose credentials, configuration files, source code, build secrets, and other CI/CD data, granting arbitrary file disclosure. The vulnerability is a classic directory traversal flaw (CWE‑22).
Affected Systems
The Allure Framework Allure2 product, specifically all 2.x releases prior to 2.39.0, is affected. Users who run the bundled HTTP server via the 'allure serve' or 'allure open' commands without updating to the patched version are at risk. The attack works regardless of the test report end‑user, as the vulnerability exists in the generic server component.
Risk and Exploitability
The flaw carries a CVSS score of 6.2, indicating moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw if they can reach the Allure server—either locally or by configuring the host option to expose it. They can then send crafted requests containing parent‑directory references or percent‑encoded segments to read files outside the report directory, potentially exposing highly confidential information.
OpenCVE Enrichment
Github GHSA