Junglewise Threat Intelligence

CVE-2026-8115: gyoridavid short-video-maker path traversal in REST API

CVE-2026-8115 · Severity: medium · CVSS 5.3 · Published 2026-05-08

Vendors: npm.

Executive brief

short-video-maker is a tool used to automate the creation of short-form videos for platforms like TikTok and YouTube. A security vulnerability allows remote attackers to access sensitive files on the server that should be restricted. This could lead to the exposure of system configuration files or other private data, potentially compromising the security of the hosting environment.

Technical details

A path traversal vulnerability (CWE-22) exists in short-video-maker versions up to 1.3.4 within the REST API component. The vulnerability is located in 'src/server/routers/rest.ts', specifically affecting the '/api/tmp/:tmpFile' and '/api/music/:fileName' routes. The application concatenates user-provided route parameters ('req.params.tmpFile' and 'req.params.fileName') with base directory paths using 'path.join' and passes the result to 'fs.createReadStream' without proper validation or normalization. A remote, unauthenticated attacker can use '..%2f' sequences to escape the intended directories and read arbitrary files accessible to the server process. As of the advisory date, no official patch has been released.

Affected products

  • gyoridavid short-video-maker <= 1.3.4

Timeline

  • 2026-04-20: disclosed: Vulnerability reported to the maintainer via GitHub issue
  • 2026-05-07: advisory: NVD published CVE-2026-8115
  • 2026-05-08: advisory: GitHub Advisory GHSA-935g-9rq5-q95c published

References