{"id":"CVE-2024-43035","aliases":["GHSA-9fv2-c7v6-p45w"],"url":"https://o3.security/vulnerability/CVE-2024-43035","summary":"Fonoster is vulnerable to directory traversal","details":"Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE: serveFiles exists in 0.5.5 but not in the next release, 0.6.1.","published":"2026-03-05T00:00:00Z","modified":"2026-08-12T03:51:22.615228022Z","cvss":{"score":5.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fonoster/voice","fixedVersion":"0.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/fonoster/fonoster/blob/4a1438d9dedeaf7b2a5b6a50d5e233f994e2b2cf/mods/voice/src/utils.ts#L66-L70"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43035.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43035"},{"type":"ARTICLE","url":"https://zeropath.com/blog/fonoster-voiceserver-lfi-vulnerability"},{"type":"PACKAGE","url":"https://github.com/fonoster/fonoster"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.615228022Z"}}