Summary
A critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leading directly to remote code execution (RCE).
Authentication with a known username is required.
Common Vulnerabilities and Exposures (CVE)
CVE-2026-54675
GitHub Security Advisory (GHSA)
GHSA-95gm-cmxf-cv8v
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green