Executive brief
A web application feature that serves custom sound files is vulnerable to an unauthenticated path traversal attack. An attacker can exploit this to read arbitrary files from the server, potentially exposing sensitive configuration files, credentials, or other confidential data—without requiring any authentication or special privileges.
Technical details
A path traversal (local file inclusion) vulnerability exists in the /custom-sounds/ endpoint when CustomSounds storage is configured to use the FileSystem backend. The vulnerability allows an unauthenticated attacker to escape the intended base directory by injecting "../" sequences in the request path. By crafting specially formed requests, an attacker can read arbitrary files outside the intended custom-sounds directory. The attack requires no authentication and is accessible over the network. A fix or patch status is not specified in the advisory.
Affected products
- <UNKNOWN>
Timeline
- 2026-08-04: disclosed