Beveiligingsadvies

CVE-2026-43624

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-01 18:16:10
Laatst bijgewerkt 2026-07-14 20:01:08
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-supplied project names directly to os.path.join() without validating the resulting path stays within the intended base directory. Attackers can supply absolute path arguments such as /tmp/EVIL to override the base directory entirely and create arbitrary directories with attacker-controlled JSON content at any filesystem path writable by the server process.