Back to list

short-video-maker has a path traversal vulnerability — CVE-2026-8115

GitHub · GitHub · CVE-2026-8115

ID
CVE-2026-8115
Date
Updated
Activity
Source
GitHub
Vendor
GitHub
Threat
medium
CVSS
5.5
EPSS
0.00044

Summary

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through…

Product

npm: short-video-maker

What to do

General, cautious steps (verify details in the official source):

  • Review exposure and plan remediation based on risk and environment.
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Related advisories