A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory traversal via absolute paths or ../ sequences to read sensitive system files.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mustafaakin
Mustafaakin cast-localvideo |
|
| Vendors & Products |
Mustafaakin
Mustafaakin cast-localvideo |
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory traversal via absolute paths or ../ sequences to read sensitive system files. | |
| Title | mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published: 2026-08-10T10:40:49.281Z
Updated: 2026-08-10T17:51:58.118Z
Reserved: 2026-08-10T10:32:53.853Z
Link: CVE-2026-72571
Updated: 2026-08-10T17:51:54.528Z
Status : Received
Published: 2026-08-10T11:17:29.760
Modified: 2026-08-10T18:18:51.420
Link: CVE-2026-72571
No data.