๐Ÿ” CVE Alert

CVE-2024-43035

MEDIUM 5.8
CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE: serveFiles exists in 0.5.5 but not in the next release, 0.6.1.

CWE CWE-24
Vendor fonoster
Product fonoster
Published Mar 5, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for fonoster fonoster

Be the first to know when new medium vulnerabilities affecting fonoster fonoster are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Fonoster / Fonoster
0.5.5 < 0.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fonoster/fonoster/blob/4a1438d9dedeaf7b2a5b6a50d5e233f994e2b2cf/mods/voice/src/utils.ts#L66-L70 zeropath.com: https://zeropath.com/blog/fonoster-voiceserver-lfi-vulnerability