Junglewise Threat Intelligence

CVE-2026-72571: mustafaakin cast-localvideo path traversal in file handler

CVE-2026-72571 · Severity: high · CVSS 7.5 · Published 2026-08-10

Executive brief

cast-localvideo is a Node.js application that streams local video files to Chromecast devices. A path traversal vulnerability in the file handler allows unauthenticated attackers to read any file on the server by manipulating directory parameters, potentially exposing sensitive system files and application data.

Technical details

The vulnerability is a path traversal flaw in app.js (lines 151-153) where the user-supplied req.body.dir parameter is passed directly to res.sendFile() without sanitization. An attacker can bypass directory restrictions using absolute paths or ../ directory traversal sequences to access arbitrary files on the server. The vulnerability requires network access to the application (typically localhost:8000 or network-exposed instance) but no authentication. An attacker can read any file accessible to the Node.js process, including system files, configuration files, and private application data. Patches may be available in newer versions; users should implement input validation and path canonicalization.

Affected products

  • mustafaakin cast-localvideo all versions

Timeline

  • 2026-08-10: disclosed

References