HIGH
mustafaakin
CVE published 2026-08-10
CVE-2026-72571
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:29.760Z and has not been modified since then. The mustafaakin/cast-localvideo application has a path traversal vulnerability. The app.js file, specifically at lines 151-153, uses the req.body.dir parameter directly in res.sendFile() without sanitization. This allows an unauthenticated remot [truncated]