GHSA-935g-9rq5-q95c

Suggest an improvement
Source
https://github.com/advisories/GHSA-935g-9rq5-q95c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-935g-9rq5-q95c/GHSA-935g-9rq5-q95c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-935g-9rq5-q95c
Aliases
  • CVE-2026-8115
Published
2026-05-08T00:31:35Z
Modified
2026-05-13T01:56:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
short-video-maker has a path traversal vulnerability
Details

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-13T01:37:38Z",
    "nvd_published_at":  "2026-05-07T23:16:33Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / short-video-maker

Package

Name
short-video-maker
View open source insights on deps.dev
Purl
pkg:npm/short-video-maker

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.3.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-935g-9rq5-q95c/GHSA-935g-9rq5-q95c.json"