Description
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/main/java/io/qameta/allure/Commands.java and passes the percent-decoded request path to reportDirectory.resolve() without normalizing the result or confirming that it remains inside that directory. An unauthenticated client that can reach the server can submit parent-directory segments, including percent-encoded segments, and cause serveFile() to return any regular file readable by the Allure process. The server binds to localhost by default, but the --host option can expose it to other systems, and local users, adjacent containers, or browser-origin attacks may reach a local listener. This can disclose credentials, configuration, source code, build secrets, and other CI/CD data. This issue is fixed in version 2.39.0.
Published: 2026-09-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted file read via path traversal
Action: Immediate Patch
AI Analysis

Impact

Allure 2’s HTTP server, launched by the allure serve and allure open commands, handles request paths by decoding the URI and resolving them in the report directory. In versions before 2.39.0, the server does not normalize the resolved path or verify that it stays within the report directory. An unauthenticated adversary able to reach the server can include parent-directory segments, including percent-encoded ones, in the request path, causing the server to serve any regular file that the Allure process can read. The server defaults to binding to localhost, but the --host option can expose it to other systems; local users, adjacent containers, or browser‑origin attacks may therefore reach the listener. As a result, the flaw can disclose credentials, configuration files, source code, build secrets, and other CI/CD data, granting arbitrary file disclosure. The vulnerability is a classic directory traversal flaw (CWE‑22).

Affected Systems

The Allure Framework Allure2 product, specifically all 2.x releases prior to 2.39.0, is affected. Users who run the bundled HTTP server via the 'allure serve' or 'allure open' commands without updating to the patched version are at risk. The attack works regardless of the test report end‑user, as the vulnerability exists in the generic server component.

Risk and Exploitability

The flaw carries a CVSS score of 6.2, indicating moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw if they can reach the Allure server—either locally or by configuring the host option to expose it. They can then send crafted requests containing parent‑directory references or percent‑encoded segments to read files outside the report directory, potentially exposing highly confidential information.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Allure 2.39.0 or later, which fixes the path normalization check.
  • If upgrading is not immediately possible, ensure the server binds only to localhost or the loopback interface, preventing external clients from connecting.
  • Apply network controls (firewalls or host‑based rules) to block traffic to the Allure server port from unauthorized sources, limiting exposure even if the server is bound to a more permissive host.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-82cg-3hv7-74gc Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Allure-framework
Allure-framework allure2
Vendors & Products Allure-framework
Allure-framework allure2

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/main/java/io/qameta/allure/Commands.java and passes the percent-decoded request path to reportDirectory.resolve() without normalizing the result or confirming that it remains inside that directory. An unauthenticated client that can reach the server can submit parent-directory segments, including percent-encoded segments, and cause serveFile() to return any regular file readable by the Allure process. The server binds to localhost by default, but the --host option can expose it to other systems, and local users, adjacent containers, or browser-origin attacks may reach a local listener. This can disclose credentials, configuration, source code, build secrets, and other CI/CD data. This issue is fixed in version 2.39.0.
Title Allure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File Read
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Allure-framework Allure2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:23:53.025Z

Reserved: 2026-06-17T16:29:38.865Z

Link: CVE-2026-55846

cve-icon Vulnrichment

Updated: 2026-09-16T15:23:46.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:55.830

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-55846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')