#CurrentDirectory
Project: microsoft/typescript-go
File: internal/tspath/path.go:323

func GetNormalizedAbsolutePath(fileName string, currentDirectory string) string

SVG: dark, light
September 9, 2025 at 9:37 AM
CVE-2026-42605 - AzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution via Media Upload
CVE ID : CVE-2026-42605

Published : May 9, 2026, 8:16 p.m. | 33 minutes ago

Description : AzuraCast is a self-hosted, all-in-one web radio management...
CVE-2026-42605 - AzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution via Media Upload
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the default), an authenticated user with media management permissions can …
cvefeed.io
May 9, 2026 at 9:11 PM
📌 CVE-2026-42605 - AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js medi... https://www.cyberhub.blog/cves/CVE-2026-42605
CVE-2026-42605
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem s
www.cyberhub.blog
May 18, 2026 at 4:37 AM
May 24, 2025 at 11:31 AM