CVE Explorer
CVE-2026-27897
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the file path, the API does not validate the filename string before it is processed by the backends filesystem logic. Because the API is unauthenticated and the CORS configuration in app.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Vociferous","vendor":"WanderingAstronomer","versions":[{"status":"affected","version":"< 4.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/WanderingAstronomer/Vociferous/security/advisories/GHSA-7cpr-frgj-h85v","tags":["x_refsource_CONFIRM"],"url":"https://github.com/WanderingAstronomer/Vociferous/security/advisories/GHSA-7cpr-frgj-h85v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:01184ce1fb8d60bae6608abe25faea98cfaa4418190430091bdd35b5b6d72318 · sha256:608ed95d937376f5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.