mediumCVSS 5.3Vulnerability

CVE-2026-8115

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
short-video-maker has a path traversal vulnerability
epss_score
0.00575
cvss_score
5.3
ghsa_published
2026-05-08T00:31:35Z
source_url
https://github.com/advisories/GHSA-935g-9rq5-q95c
ghsa_updated
2026-05-13T01:37:40Z
ghsa_id
GHSA-935g-9rq5-q95c
cve_id
CVE-2026-8115
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
false
epss_percentile
0.44277

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/short-video-maker

AFFECTS (1)

[Software]npm/short-video-maker

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8115 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal