Executive brief
Summarize is a tool used to process and extract information from media. A security flaw in its background service allows an authorized user or a malicious local application to force the tool to write or delete files in unintended folders on the computer. This could lead to the corruption of system files or the loss of important data if the tool is manipulated to target sensitive directories.
Technical details
A path traversal vulnerability exists in the /v1/summarize daemon endpoint of the Summarize package. The root cause is the 'slidesDir' request parameter being passed to a path resolution function without proper sandboxing, allowing absolute paths or '..' sequences to escape the intended directory. An authenticated attacker with a valid bearer token can exploit this to write 'slide_*.png' and 'slides.json' files to any writable directory on the host. Furthermore, repeat requests can trigger a cleanup routine that deletes files matching those naming patterns in the targeted directory. The issue is fixed in version 0.15.0 by ignoring the user-supplied slidesDir in daemon mode and forcing output to a pre-defined sandbox.
Affected products
- steipete @steipete/summarize < 0.15.0
Timeline
- 2026-05-12: other: Fix submitted via pull request
- 2026-05-18: advisory: GitHub Advisory and NVD entry published
- 2026-05-18: patched: Version 0.15.0 released
References
- https://github.com/steipete/summarize/pull/220
- https://github.com/steipete/summarize/commit/ec8efd63295656fbfe8743620179c489bc5a242f
- https://github.com/steipete/summarize/releases/tag/v0.15.2
- https://www.vulncheck.com/advisories/summarize-path-traversal-via-slidesdir-parameter
- https://github.com/steipete/summarize/releases/tag/v0.15.1