Impact
The vulnerability resides in the createParsedTrack.ts module of FLB‑Music‑Player, where improper handling of the path.join function allows an attacker with local execution privileges to manipulate file paths. This path traversal flaw can be exploited to read or potentially write files outside the intended directory, leading to confidential data exposure or code execution if write access is permitted. The impact is confined to local systems because the attack requires local access to the application process.
Affected Systems
FLB‑Music‑Player versions 1.1.8, 1.1.9, 1.2.0, and 1.2.1 running on any platform are impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity, and no EPSS information is available. The flaw is listed as not in CISA’s KEV catalog, and the exploit can only be performed locally. Because the vendor has not yet issued a patch, the likelihood of an exploit depends on local attacker presence. The path traversal does not require additional network exposure and can be triggered by any component that calls createParsedTrack with a crafted argument.
OpenCVE Enrichment