External Control of File Name or Path Affecting phantom-audio package, versions [,1.3.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about External Control of File Name or Path vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PHANTOMAUDIO-17911226
  • published9 Jul 2026
  • disclosed9 Jul 2026
  • creditUnknown

Introduced: 9 Jul 2026

CVE NOT AVAILABLE CWE-22  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade phantom-audio to version 1.3.1 or higher.

Overview

phantom-audio is an AI audio engineering system -- makes Claude a professional audio engineer

Affected versions of this package are vulnerable to External Control of File Name or Path via unconfined tool path handling and lack of input size restrictions. An attacker can write or overwrite arbitrary files accessible to the process user, potentially leading to local code execution, or exhaust system memory by submitting specially crafted compressed audio files that expand to large sizes during decoding.

Workaround

This vulnerability can be mitigated by setting the PHANTOM_OUTPUT_DIR (and optionally PHANTOM_AUDIO_DIR) environment variables to dedicated directories before starting the server.

CVSS Base Scores

version 4.0
version 3.1