Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit this to write slide_*.png and slides.json files to any writable directory and subsequently delete matching files at the specified location through repeat extraction.
History

Tue, 19 May 2026 01:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:steipete:summarize:*:*:*:*:*:*:*:*

Mon, 18 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Steipete
Steipete summarize
Vendors & Products Steipete
Steipete summarize

Mon, 18 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 May 2026 19:00:00 +0000

Type Values Removed Values Added
Description Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit this to write slide_*.png and slides.json files to any writable directory and subsequently delete matching files at the specified location through repeat extraction.
Title Summarize < 0.15.1 Path Traversal via slidesDir Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-18T18:52:08.528Z

Updated: 2026-05-18T19:09:46.659Z

Reserved: 2026-05-11T14:14:49.613Z

Link: CVE-2026-45242

cve-icon Vulnrichment

Updated: 2026-05-18T19:09:43.149Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-18T19:16:28.240

Modified: 2026-05-19T01:34:29.797

Link: CVE-2026-45242

cve-icon Redhat

No data.