Steipete Summarize Path Traversal Vulnerability in Daemon Endpoint

Vulnerability

A path traversal vulnerability has been identified in the Steipete Summarize application, specifically in versions prior to 0.15.1. The issue resides within the '/v1/summarize' daemon endpoint, where authenticated users can manipulate the 'slidesDir' request parameter to write files to arbitrary directories. By providing an absolute path or a directory traversal sequence, attackers can exploit this vulnerability to save 'slide_*.png' and 'slides.json' files in any writable location. Furthermore, the vulnerability allows for the deletion of these files through repeated extractions.

Impact

Exploitation of this vulnerability could lead to unauthorized file writing and deletion, potentially disrupting normal application operations or causing data loss.

Reproduction

To reproduce this vulnerability, send a request to the '/v1/summarize' daemon endpoint with the 'slidesDir' parameter set to an absolute path or a directory traversal sequence. This will result in the 'slide_*.png' and 'slides.json' files being written to the specified location. The vulnerability can be further exploited by repeating the extraction process to delete the matching files.

Remediation

Users are advised to update to Steipete Summarize version 0.15.2 or later, where this vulnerability has been fixed.

Added: May 18, 2026, 7:21 PM
Updated: May 18, 2026, 7:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
5.8
remediation
0.0
relevance
8.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.