๐Ÿ” CVE Alert

CVE-2026-101036

MEDIUM 5.3

FLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversal

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-22
Vendor flb-music
Product flb-music-player
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for flb-music flb-music-player

Be the first to know when new medium vulnerabilities affecting flb-music flb-music-player are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

FLB-Music / FLB-Music-Player
1.1.8 1.1.9 1.2.0 1.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/410904 vuldb.com: https://vuldb.com/vuln/410904/cti vuldb.com: https://vuldb.com/cve/CVE-2026-101036 vuldb.com: https://vuldb.com/submit/926475 allannjuguna.github.io: https://allannjuguna.github.io/blog/flb_music/flb_music_player/

Credits

๐Ÿ” Allan Njuguna (VulDB User) VulDB CNA Team