In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about External Control of File Name or Path vulnerabilities in an interactive lesson.
Start learningUpgrade phantom-audio to version 1.3.1 or higher.
phantom-audio is an AI audio engineering system -- makes Claude a professional audio engineer
Affected versions of this package are vulnerable to External Control of File Name or Path via unconfined tool path handling and lack of input size restrictions. An attacker can write or overwrite arbitrary files accessible to the process user, potentially leading to local code execution, or exhaust system memory by submitting specially crafted compressed audio files that expand to large sizes during decoding.
This vulnerability can be mitigated by setting the PHANTOM_OUTPUT_DIR (and optionally PHANTOM_AUDIO_DIR) environment variables to dedicated directories before starting the server.