CVE-2026-8115

MEDIUM

gyoridavid short-video-maker REST API rest.ts path traversal

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-361903 | gyoridavid short-video-maker REST API rest.ts path traversal
https://vuldb.com/vuln/361903
Signature, Permissions Required signature permissions-required
VDB-361903 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/361903/cti
Third Party Advisory third-party-advisory
Submit #808258 | gyoridavid short-video-maker 1.3.4 Path Traversal
https://vuldb.com/submit/808258

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (6)
gyoridavid/short-video-maker 1.3.0
gyoridavid/short-video-maker 1.3.1
gyoridavid/short-video-maker 1.3.2
gyoridavid/short-video-maker 1.3.3
gyoridavid/short-video-maker 1.3.4
npm/short-video-maker 0 - 1.3.4npm
Published May 07, 2026
Tracked Since May 08, 2026