LOW
FLB-Music
CVE published 2026-09-28
CVE-2026-101036
A vulnerability was found in FLB-Music FLB-Music-Player versions 1.1.8, 1.1.9, 1.2.0, and 1.2.1. The issue is in the path.join function in the /src/main/core/createParsedTrack.ts file, which is vulnerable to path traversal attacks. The attack requires local access. The exploit has been publicly disclosed, and the vendor did not respond to early disclosure.