WhisperX tag archive

#Arbitrary File Write

This page collects WhisperX intelligence signals tagged #Arbitrary File Write. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (4)

The Lab · 2026-03-26 16:27:21 · GitHub Issues

1. Black Code Formatter Security Flaw (CVE-2026-32274): Arbitrary File Write via Cache Filename

A critical security vulnerability has been disclosed in the widely-used Python code formatter, Black. The flaw, tracked as CVE-2026-32274, stems from improper sanitization of user input when generating cache filenames. Specifically, the value of the `--python-cell-magics` command-line argument is incorporated into a ca...

The Lab · 2026-04-17 03:22:40 · GitHub Issues

2. CVE-2025-59342: Critical Arbitrary File Write Vulnerability in esm.sh (v136 and earlier)

A critical path traversal vulnerability in the popular JavaScript CDN and ESM transpiler, esm.sh, has been publicly documented, allowing attackers to write arbitrary files to the server. The flaw, tracked as CVE-2025-59342, affects versions v136 and earlier. This is not a theoretical risk; the vulnerability template ha...

The Lab · 2026-05-02 21:54:09 · GitHub Issues

3. CVE-2026-24486: Path Traversal Flaw in python-multipart Exposes Systems to Arbitrary File Write

A Path Traversal vulnerability has been identified in python-multipart versions up to 0.0.20, enabling attackers to write uploaded files to arbitrary filesystem locations under specific non-default configuration conditions. The flaw, catalogued as CVE-2026-24486, resides in how the library handles file path constructio...

The Lab · 2026-05-10 15:32:02 · GitHub Issues

4. Rollup JavaScript Bundler Vulnerability Allows Arbitrary File Write via Path Traversal

A critical path traversal vulnerability has been disclosed in Rollup, the widely-used JavaScript module bundler, affecting versions 4.x and current source code. Tracked as CVE-2026-27606 and published through GitHub's security advisory system (GHSA-mw96-cpmx-2vgc), the flaw enables attackers to manipulate output filena...