An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3514640 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-04 01:16
Updated : 2026-09-09 15:41
NVD link : CVE-2026-56845
Mitre link : CVE-2026-56845
CVE.ORG link : CVE-2026-56845
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
