---
id: CVE-2026-45242
title: >-
  Summarize prior to 0.15.1 contains a path traversal vulnerability in the
  /v1/summarize daemon endpoint that allows authenticated callers to write files
  to arbitrary directories by supplying an absolute path or directory traversal
  sequenc…
summary: >-
  Summarize prior to 0.15.1 contains a path traversal vulnerability in the
  /v1/summarize daemon endpoint that allows authenticated callers to write files
  to arbitrary directories by supplying an absolute path or directory traversal
  sequenc…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-862
vendor: steipete
product: summarize
affected:
  - summarize < 0.15.1
patched:
  - summarize 0.15.1
published: '2026-05-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:16.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45242'
references:
  - url: >-
      https://github.com/steipete/summarize/commit/ec8efd63295656fbfe8743620179c489bc5a242f
    label: disclosure@vulncheck.com
  - url: 'https://github.com/steipete/summarize/pull/220'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/steipete/summarize/releases/tag/v0.15.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/summarize-path-traversal-via-slidesdir-parameter
    label: disclosure@vulncheck.com
  - url: 'https://github.com/steipete/summarize/pull/220'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-18T19:09:26.331135Z'
epss: 0.00714
epssPercentile: 0.52198
ingestedAt: '2026-10-08T16:52:14.680Z'
---

## Overview

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit this to write slide_*.png and slides.json files to any writable directory and subsequently delete matching files at the specified location through repeat extraction.

## Affected

- `summarize < 0.15.1`

## Remediation

Upgrade past the affected range:

- `summarize 0.15.1`
