VDB
Sign up
MEDIUM5.8

GHSA-9fv2-c7v6-p45w

Fonoster is vulnerable to directory traversal

Quick fix

GHSA-9fv2-c7v6-p45w — @fonoster/voice: upgrade to the fixed version with the command below.

npm install @fonoster/voice@0.6.1

Details

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE: serveFiles exists in 0.5.5 but not in the next release, 0.6.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fonoster/voice
Introduced in: 0.5.5Fixed in: 0.6.1
Fixnpm install @fonoster/voice@0.6.1

References