libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43685.json"