PatchSiren cyber security CVE debrief
CVE-2026-108603 addsumtech CVE debrief
CVE-2026-108603 is a path traversal vulnerability in slide-maker through 5.8.0. Attackers can write image files outside the output directory via manifest-supplied filenames, potentially creating directories and overwriting existing files at arbitrary paths. Defenders should assess exposure and prioritize verification and remediation efforts, focusing on updating to a fixed version and monitoring for suspicious activity. This vulnerability allows attackers to influence deck source material, leading to potential unauthorized file creation and data integrity issues.
- Vendor
- addsumtech
- Product
- slide-maker
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for slide-maker deployments should assess exposure and prioritize verification and remediation efforts. This includes updating to a fixed version, monitoring for suspicious activity, and restricting write access to the output directory. Additionally, security teams and vulnerability management teams should review the vulnerability and plan for potential mitigations.
Why it matters
CVE-2026-108603 is a path traversal vulnerability in slide-maker that allows attackers to write image files outside the output directory. Defenders should prioritize verifying and updating to a fixed version, monitoring for suspicious activity, and restricting write access to the output directory.
- Potential unauthorized file creation
- Possible data integrity issues
- Required verification of affected versions and remediation
Technical summary
The slide-maker package through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py. This allows attackers to write image files outside the output directory via manifest-supplied filenames, potentially creating directories and overwriting existing files at arbitrary paths. The vulnerability can be exploited by influencing deck source material, leading to potential unauthorized file creation and data integrity issues. Defenders should prioritize verifying and updating to a fixed version of slide-maker, monitoring for suspicious image file creations, and restricting write access to the output directory.
Defensive priority
Defenders should prioritize verifying and updating to a fixed version of slide-maker, if available, and monitoring for suspicious image file creations.
Recommended defensive actions
- Verify and update to a fixed version of slide-maker, if available
- Monitor for suspicious image file creations
- Review and restrict write access to the output directory
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Additional information on affected versions and remediation is needed. Defenders should verify and update to a fixed version of slide-maker, monitor for suspicious image file creations, and review and restrict write access to the output directory. The vulnerability is caused by a path traversal issue in generate_images_openai.py, which allows attackers to write image files outside the output directory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108603 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108603
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108603 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108603
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/addsumtech/slides_maker
-
Source reference
Unverified legacy reference
URL: https://github.com/addsumtech/slides_maker/blob/3767cc346d63ef1646082c87f15fbf0be582b152/skills/slide-maker/scripts/generate_images_openai.py
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/BJnX7pIifx
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/slide-maker-through-5.8.0-path-traversal-via-generate-images-openai-py
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.