← Vulnerability feed

Vulnerability record · CVE-2024-45388 · published 2 September 2024

CVE-2024-45388: Hoverfly simulation API path traversal allows arbitrary file read

Hoverfly · Hoverfly

Hoverfly's POST /api/v2/simulation handler builds a file path from user-supplied input without confirming the resolved path stays inside the configured responses body files base directory. Although absolute paths are rejected, ../ segments let an attacker escape the base path and read arbitrary files from the Hoverfly server. This is a high-severity information disclosure issue in a tool often run in shared test and CI environments.

7.5 CVSS 3.1 High EPSS 56% · top 1.0% CWE-200 · Information exposureCWE-22 · Path traversal
7.5CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature can be abused by an attacker to read arbitrary files from the Hoverfly server. Note that, although the code prevents absolute paths from being specified, an attacker can escape out of the `hf.Cfg.ResponsesBodyFilesPath` base path by using `../` segments and reach any arbitrary files. This issue was found using the Uncontrolled data used in path expression CodeQL query for python. Users are advised to make sure the final path (`filepath.Join(hf.Cfg.ResponsesBodyFilesPath, filePath)`) is contained within the expected base path (`filepath.Join(hf.Cfg.ResponsesBodyFilesPath, "/")`). This issue is also tracked as GHSL-2023-274.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityNetwork-reachable unauthenticated arbitrary file read with a high EPSS score and public exploit detail, though no confirmed in-the-wild exploitation.

What it is

Hoverfly's POST /api/v2/simulation handler builds a file path from user-supplied input without confirming the resolved path stays inside the configured responses body files base directory. Although absolute paths are rejected, ../ segments let an attacker escape the base path and read arbitrary files from the Hoverfly server. This is a high-severity information disclosure issue in a tool often run in shared test and CI environments.

Impact

An attacker can read any file the Hoverfly process can access, exposing configuration, credentials, tokens and source material on the host. There is no integrity or availability impact; the gain is confidential data.

Attack surface

Reached over the network through the Hoverfly HTTP API endpoint POST /api/v2/simulation; the CVSS vector shows no privileges and no user interaction required. Any party able to reach the API can attempt the traversal.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.556 (99th percentile), and the vendor advisory reference is tagged Exploit, indicating public exploit detail exists.

What to do

  • Upgrade Hoverfly to v1.10.3 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict network access to the Hoverfly API to trusted clients only.
  • Validate that any resolved file path is contained within the configured responses body files base path before use.
  • Run Hoverfly with least privilege and avoid placing sensitive files within reach of the service account.
  • Review exposure of the simulation API in CI and shared test environments and disable it where not needed.

Detection

  • Monitor Hoverfly logs and API access logs for POST /api/v2/simulation requests containing ../ sequences or unusual file paths.
  • Alert on file reads by the Hoverfly process outside its configured responses body files directory.
  • Audit outbound or subsequent use of files read via the simulation endpoint for signs of credential or configuration exfiltration.
  • Check for unexpected simulation objects or response body file references created through the API.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45388 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54123Hoverfly improper input validation vulnerabilityHoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injec…EPSS 11%7.8CVE-2025-54376Hoverfly information exposure vulnerabilityHoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…EPSS 0.71%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed5.5CVE-2026-20805Windows Desktop Window Manager information disclosureDesktop Windows Manager (DWM) in Microsoft Windows exposes sensitive information to an unauthorized actor, allowing a local attacker with existing ac…KEVEPSS 7.2%analysed7.5CVE-2021-41277Metabase custom GeoJSON map feature allows local file inclusionMetabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. …KEVEPSS 97%analysed8.6CVE-2024-24919Check Point Security Gateway information disclosure via remote access VPNCheck Point Security Gateways with Remote Access VPN or Mobile Access Software Blades enabled expose information to an unauthenticated attacker reach…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-45388), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.