CVE-2026-53449Medium· 6.0▾ SunlitCoturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version 4.13.0.
coturn < 4.13.0Upgrade past the affected range:
coturn 4.13.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68553High· 7.1Coturn is a free open source implementation of TURN and STUN Server
CVE-2026-68554Low· 2.3Coturn is a free open source implementation of TURN and STUN Server
CVE-2026-53448High· 7.2Coturn is a free open source implementation of TURN and STUN Server
CVE-2026-26158High· 7.0A flaw was found in BusyBox
CVE-2026-26157High· 7.0A flaw was found in BusyBox
CVE-2025-68428High· 7.5jsPDF is a library to generate PDFs in JavaScript