Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module

Summary

A critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leading directly to remote code execution (RCE).

Authentication with a known username is required.

Common Vulnerabilities and Exposures (CVE)

CVE-2026-54675

GitHub Security Advisory (GHSA)

GHSA-95gm-cmxf-cv8v

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.