PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108603 addsumtech CVE debrief

CVE-2026-108603 is a path traversal vulnerability in slide-maker through 5.8.0. Attackers can write image files outside the output directory via manifest-supplied filenames, potentially creating directories and overwriting existing files at arbitrary paths. Defenders should assess exposure and prioritize verification and remediation efforts, focusing on updating to a fixed version and monitoring for suspicious activity. This vulnerability allows attackers to influence deck source material, leading to potential unauthorized file creation and data integrity issues.

Vendor
addsumtech
Product
slide-maker
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for slide-maker deployments should assess exposure and prioritize verification and remediation efforts. This includes updating to a fixed version, monitoring for suspicious activity, and restricting write access to the output directory. Additionally, security teams and vulnerability management teams should review the vulnerability and plan for potential mitigations.

Why it matters

CVE-2026-108603 is a path traversal vulnerability in slide-maker that allows attackers to write image files outside the output directory. Defenders should prioritize verifying and updating to a fixed version, monitoring for suspicious activity, and restricting write access to the output directory.

  • Potential unauthorized file creation
  • Possible data integrity issues
  • Required verification of affected versions and remediation

Technical summary

The slide-maker package through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py. This allows attackers to write image files outside the output directory via manifest-supplied filenames, potentially creating directories and overwriting existing files at arbitrary paths. The vulnerability can be exploited by influencing deck source material, leading to potential unauthorized file creation and data integrity issues. Defenders should prioritize verifying and updating to a fixed version of slide-maker, monitoring for suspicious image file creations, and restricting write access to the output directory.

Defensive priority

Defenders should prioritize verifying and updating to a fixed version of slide-maker, if available, and monitoring for suspicious image file creations.

Recommended defensive actions

  • Verify and update to a fixed version of slide-maker, if available
  • Monitor for suspicious image file creations
  • Review and restrict write access to the output directory
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Additional information on affected versions and remediation is needed. Defenders should verify and update to a fixed version of slide-maker, monitor for suspicious image file creations, and review and restrict write access to the output directory. The vulnerability is caused by a path traversal issue in generate_images_openai.py, which allows attackers to write image files outside the output directory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108603 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108603

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108603 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108603

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.