Path Traversal Vulnerability in Slide-Maker by Addsum Technologies
CVE-2026-108603
4.8MEDIUM
What is CVE-2026-108603?
The Slide-Maker application, up to version 5.8.0, is susceptible to a path traversal vulnerability found in the generate_images_openai.py script. This flaw allows attackers to manipulate the filenames in the image prompt manifest, enabling them to write image files outside the designated output directory. By utilizing directory traversal sequences such as '../', or through symlinked filenames, attackers can create arbitrary directories and overwrite existing files, potentially compromising system integrity and security. It is crucial for users of Slide-Maker to apply the necessary security patches and review their deployment configurations to mitigate these risks.
Affected Version(s)
slide-maker 0 <= 5.8.0
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
