Sceawere

Vulnerability Detail

CVE-2026-101036UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FLB-Music Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
FLB-Music
Product
FLB-Music-Player
Attack Type
Path Traversal
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T10:16:42.630Z",
  "pubdate": "2026-09-28T10:16:42.630Z",
  "executiveSummary": "A path traversal vulnerability has been identified in FLB-Music-Player versions 1.1.8, 1.1.9, 1.2.0, and 1.2.1.\nThe vulnerability resides in the path.join function within the /src/main/core/createParsedTrack.ts file, which inadequately sanitizes user-supplied input.\nThis flaw allows a local attacker to manipulate file paths, potentially leading to unauthorized access to files outside of the intended directory structure.\nThe vulnerability is limited to local exploitation, requiring the attacker to have local access to the system or the ability to influence the local input vectors processed by the application.\nThe vendor was notified of the disclosure but has remained unresponsive, leaving the vulnerability unpatched in the affected versions.\nThe risk implication involves unauthorized file system traversal, which could be leveraged to access sensitive configuration files or other user data depending on the application's execution context.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of special elements used in path manipulation within the path.join function in /src/main/core/createParsedTrack.ts.\nIn the affected versions of FLB-Music-Player, the application processes track-related paths using the path.join utility. Because the input provided to this function is not effectively validated or constrained against directory traversal sequences (such as '../'), an attacker can construct malicious input that escapes the intended base directory.\nThe attack flow requires an attacker to interact with the application’s file parsing logic. By injecting path traversal sequences into the track source or metadata fields that are subsequently processed by createParsedTrack.ts, the attacker causes the application to resolve and access arbitrary files on the underlying file system.\nThe exploitation method relies on the application concatenating user-controlled inputs with application-defined base paths. When the path.join function resolves these strings, the '..' sequences move the file pointer up the directory tree.\nBecause the attack must be carried out locally, the attacker typically requires authenticated local access to the host machine or the ability to deliver a crafted track file/metadata package to a user who then imports it into the application.\nThe post-exploitation impact includes the potential for local information disclosure. By traversing to sensitive files, an attacker may be able to read system files or application-specific data that the process has permissions to access.\nThe absence of input sanitization or strict path normalization allows the path resolution engine to process these traversal tokens as legitimate path components. There is no evidence of authentication or complex privilege requirements beyond what is necessary to interact with the application’s file parsing features on the local host.\nSince the vendor has not provided a patch, the vulnerable code in /src/main/core/createParsedTrack.ts remains susceptible to any input that passes through the affected function without prior filtering or path validation."
}
CVE-2026-101036: FLB-Music Path Traversal Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere