PT-2026-45518 · Swivid+1 · F5-Tts
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
F5-TTS versions prior to 1.1.21
Description
A path traversal issue exists in the finetune Gradio handlers. Unauthenticated attackers can write arbitrary files by providing unsanitized project names that are passed directly to the
os.path.join() function without validation to ensure the resulting path remains within the intended base directory. By supplying absolute path arguments, such as /tmp/EVIL, an attacker can override the base directory and create directories containing attacker-controlled JSON content at any filesystem path writable by the server process.Recommendations
Update F5-TTS to version 1.1.21 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5-Tts