CVE Explorer
CVE-2026-53449
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"coturn","vendor":"coturn","versions":[{"status":"affected","version":"< 4.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-73","description":"CWE-73: External Control of File Name or Path","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55","tags":["x_refsource_MISC"],"url":"https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/references/1
{"name":"https://github.com/coturn/coturn/releases/tag/4.13.0","tags":["x_refsource_MISC"],"url":"https://github.com/coturn/coturn/releases/tag/4.13.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/adp/0/references/0
{"name":"https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af253d9c01a82ce0f1db3a36d7699c89342937463eae113ffa5b2284f614e3da · sha256:0aff0b88b6924390… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.