CVE-2026-108603
Received Received - Intake

Path Traversal in Slide-Maker via OpenAI Image Generation

Vulnerability report for CVE-2026-108603, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

slide-maker through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py that allows attackers to write image files outside the output directory via manifest-supplied filenames. Attackers can influence deck source material so the image prompt manifest contains ../ or symlinked filenames, creating directories and overwriting existing files at arbitrary paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
addsumtech slide-maker 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the slide-maker tool through version 5.8.0. It exists in the generate_images_openai.py script where attackers can manipulate filenames in a manifest to write image files outside the intended output directory. By using sequences like ../ or symlinked paths, attackers can create directories and overwrite files at arbitrary system locations.

Detection Guidance

To detect this vulnerability, inspect the slide-maker tool version and check for the presence of generate_images_openai.py in your system. Look for unexpected file writes or directory creations outside the intended output directory. Review any JSON manifests used for image generation for filenames containing ../ or absolute paths.

Impact Analysis

An attacker could overwrite critical system files, plant malicious files, or create directories in unintended locations. This could lead to system compromise, data corruption, or denial of service if important files are overwritten. The attack requires influence over the source material used to generate the slide deck.

Mitigation Strategies

Immediately update slide-maker to a version that includes path containment checks in generate_images_openai.py. If an update is unavailable, disable the OpenAI image generator component or restrict write permissions to the output directory. Review and sanitize all filenames in manifests before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108603. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart